Twitter has fixed a security flaw that could have been exploited to delete linked credit cards from all accounts, "freeing" the company from the revenue it receives from advertising .
The vulnerability was discovered by researcher Ahmed Aboul-Ela, who was rewarded with $2,800 as part of the company's new Bug Bounty .
Aboul-Ela discovered two vulnerabilities, which when combined with a specially crafted script, can be used to delete all stored credit cards from all Twitter accounts.
"The impact of the vulnerability is very large, as all it takes to delete credit cards is the credit card identifier, which consists of only six numbers," Aboul-Ela said.
“So imagine a black hat hacker who could write a simple Python code and use a simple loop for six numbers – they could delete all credit cards from all Twitter accounts, which would lead to the suspension of all Twitter advertising campaigns, with a large financial loss for the company,” he added.

