Referral rewards programs are nearly ubiquitous today, from consumer tech to SaaS companies, but are rarely given much security oversight. In this blog post we’ll dig into the common technical implementations of rewards programs on…
During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.
Read-Access to other Vestaboards.
Ability to update names of other users.
Privilege escalation from Admin to…