Labs

Walkthroughs of Uphack labs: the product the bug lives in, the request that proves it, and the check that closes it.

  1. IDOR in an SSO Investment Account Closure

    How different password and SSO confirmation paths expose an IDOR in an investment account closure endpoint, including the request comparison, vulnerable code, impact, and ownership fix.

  2. Reflected XSS via Nested Form Parameters

    How a nested digest[email] parameter becomes autofocus and onfocus attributes in a newsletter signup, including the payload, vulnerable code and fix.

  3. Base64 IDOR in a Return Credit Claim

    How a Base64-encoded return reference leads to IDOR in a financial action: the request, decoded JSON, modified payload, vulnerable code, impact, and correct ownership check.

© 2026 Uphack.io

RSS Theme