T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/backend-node/server.js:69- Finding
Unauthenticated Merchant Operations and Transaction Data Access
- Content
View full analysis
{ const { amount, custId, mobile, email, orderId } = req.body ?? {}; return initiateTransaction({ amount, custId, mobile, email, orderId, serverBaseUrl: requestBase(req) }); })); app.post("/paytm/create-subscription", withIdempotency(async (req) => { return createSubscription({ ...(req.body ?? {}), serverBaseUrl: requestBase(req) }); })); app.post("/paytm/create-link", withIdempotency(async (req) => { return createPaymentLink({ ...(req.body ?? {}), serverBaseUrl: requestBase(req) }); })); app.post("/paytm/create-qr", withIdempotency(async (req) => { return createDynamicQr({ ...(req.body ?? {}) }); })); app.post("/paytm/link-transactions", async (req, res) => { try { const out = await fetchLinkTransactions({ ...(req.body ?? {}) }); res.json(out); } catch (e) { res.status(Number(e?.httpStatus) || 500).json(payloadFromError(e)); } }); ``` ```javascript app.post("/paytm/order-status", async (req, res) => { try { const orderId = req.body?.orderId; if (!orderId) return res.status(400).json({ error: true, message: "orderId required" }); const json = await fetchOrderStatus({ orderId }); res.type("application/json").send(json); } catch (e) { res.status(500).json({ error: true, message: e?.message || String(e) }); } }); ``` ### Technical Analysis These endpoints perform privileged operations using the backend's Paytm merchant key. However, none of the route handlers authenticate ...[truncated 2484 chars]- Remediation
View remediation
