Researchers Find Major Flaw in Banking Platform Potentially Affecting Millions
Summary
A cybersecurity research team discovered a significant vulnerability in a financial services platform that has already been implemented in a large number of banking systems. If it had been successfully exploited, the flaw could have led to a potential disaster, allowing threat actors to drain the bank accounts of millions of users. The issue discovered was significant enough to be able to give potential threat actors admin access to the bank that chose to implement the platform in question. As proof of the vulnerability, Salt Labs doctored a bad request, replacing the domain of the banking institution with their own, then receiving the connection on their end. In short, this proved that the server never checks the domain string and "trusts" whatever it receives in the InstitutionURL parameter, allowing for tampering.