wiz · Crawled Jul 15, 2026

The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System

1 IoCs
Read original article ↗

AI Summary

A business-logic flaw in a B2B platform's data API allowed unauthorized access to premium contact data without spending credits. The vulnerability stemmed from the backend trusting a client-controlled boolean flag 'unmaskContactData' without validating user entitlements. This enabled free-tier users to bypass paywall restrictions and extract unmasked business emails, phone numbers, and personal information at scale. The flaw highlights a critical gap in server-side authorization enforcement, which traditional security tools failed to detect.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain app[.][REDACTED][.]com Details →