HomeSecurityAn RCE bug was discovered in Starbucks' mobile platform

An RCE bug was discovered in Starbucks' mobile platform

A potential remote code execution (RCE) vulnerability has been fixed in one of Starbucks' mobile domains.

The giant American coffee company is running a bug bounty program on HackerOne. A new vulnerability report filed by Kamil “ko2sec” Onur Özkaleli, first submitted on November 5 and made public on December 9, describes an RCE issue found on mobile.starbucks.com.sg, a platform for Singaporean.

Starbucks

According to the advisory, ko2sec discovered an .ashx endpoint on mobile.starbucks.com.sg that was intended to handle image. However, the endpoint did not restrict the files that were uploaded, meaning attackers could exploit the issue and potentially upload malicious files and remotely execute arbitrary code.

No CVE for the critical vulnerability, but it is rated 9.8. Ko2sec received $5,600 for findings .

The RCE isn’t the only bug the researcher has reported on Starbucks. In October, Ko2sec described an “account takeover exploit” on the Starbucks Singapore website that was triggered by open test. It was possible for targeted users – if they knew their email – to view their personal information and even use any funds loaded into account to make purchases.

The bug hunter received the sum of $6,000 for this report.

To date, Starbucks has received 1,068 vulnerability reports on HackerOne. The average amount paid for valid submissions ranges from $250 to $375, while critical bugs cost between $4,000 and $6,000. In total, the coffee chain has paid out over $640,000 to bug hunters.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS