An IDOR that exposed every customer account, found and closed in twelve days.
How a hands-on web + API assessment caught a broken access-control flaw automated scanners had missed for months.
THE CHALLENGE
A fast-growing fintech was preparing for a major enterprise customer’s security review and needed independent assurance that their platform could withstand a real attacker. They’d been running automated scans in CI, which came back clean, but their team suspected the scanners weren’t catching business-logic and authorization flaws. They were right to worry.
THE ENGAGEMENT
Cybros ran a two-week grey-box web application and API penetration test against a staging mirror of production, with three provisioned account roles. Testing focused on authentication, authorization, and the API endpoints behind the customer app, exactly the areas scanners struggle with.
WHAT WE FOUND
By changing a single ID in an API request, an authenticated user could pull, and alter, any other customer’s full record, including balances and PII. Sequential IDs meant the entire customer base was enumerable. It was reported inside the engagement’s Critical-notification window, not held for the final report.
Broken object-level authorization (IDOR) on the accounts API
Any user could read or modify any other account
Stored XSS in a field rendered in the support console
Cross-privilege session compromise
Missing rate limiting on login / OTP
Credential stuffing and OTP brute-force
THE OUTCOME
The engineering team shipped a centralized authorization check within days. Cybros retested and verified every Critical and High finding as closed: enumeration returned 403, XSS rendered inert, brute-force throttled. The client passed their enterprise customer’s security review, and the authorization pattern was added to their CI test suite to prevent regressions.
“Cybros found in two weeks what our scanners missed for a year, and told us exactly how to fix it.”
Head of Engineering, Series-B Fintech
READY WHEN YOU ARE
Test your series-b fintech systems the same way.
Book a free 30-minute scoping call, or download our sample report first.