The Endpoint Wasn't Vulnerable. The Attack Chain Was.
Introduction
The first finding wasn't critical.
It wasn't even particularly interesting.
There was no SQL Injection.
No Remote Code Execution.
No authentication bypass.
Just an API endpoint that shoul
danielisaace.hashnode.dev9 min read