eval.blog

Unrestricted access to any "connected pack" in docs in coda.io

Reported an Broken Access Control in coda.io where an attacker could leverage the trial feature to gain access to paid offerings.

References:

  • https://hackerone.com/reports/777942