T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/getReport.ts:59- Finding
Unauthenticated Report Lookup and Unreliable Payment Authorization
- Content
View full analysis
( `${FIXED_API_BASE}/reports/search`, { method: "POST", headers: { "Content-Type": "application/json", }, body: JSON.stringify({ filter: { profileIds: { $in: [profileId], }, }, pagination: { offset: 0, limit: 50, }, }), }, timeoutMs, ); } ``` ```ts async function getProfilePaidStatus(profileId: string, timeoutMs: number): Promise { const controller = new AbortController(); const timer = setTimeout(() => controller.abort(), timeoutMs); try { const response = await fetch(`${FIXED_API_BASE}/profiles/${encodeURIComponent(profileId)}`, { method: "GET", signal: controller.signal, }); const text = await response.text(); let parsed: unknown = null; if (text) { try { parsed = JSON.parse(text); } catch { fail(`Get profile response is not valid JSON. Status=${response.status}, body=${text}`); } } if (!parsed || typeof parsed !== "object") { fail("Get profile returned empty or invalid JSON payload."); } const result = parsed as { code?: unknown; message?: unknown; msg?: unknown; error?: unknown; errorMessage?: unknown; data?: GetProfileData; }; if (typeof result.code !== "number") { fail(`Get profile returned invalid business code. Status=${response.status}, body=${text}`); } if (result.code === 1) { return true; } if (result.code === 40 ...[truncated 3797 chars]- Remediation
View remediation
