Skip to content

bentoboxinfosec

many parts make the whole

  • Home
  • Blog
  • CTF Cheat Sheet
  • About
  • Home
  • 2024
  • December
  • 20
  • McDonald’s API EXPLOITED FOR ONE CENT DELIVERIES

McDonald’s API EXPLOITED FOR ONE CENT DELIVERIES

Posted on December 20, 2024January 20, 2025 By topbento
News

A flaw in McDonald’s McDelivery system in India could have allowed for the ability to order any number of menu items for $0.01. Sensitive information in the form of invoices for any order and the personal details for the delivery driver could also have been disclosed. This serves as a great reminder that while apps allow for customers to easily access services they can also present potential security compromises.

A great writeup on the methodology used to test the API is available here!

Tags: API Pentesting cybersecurity news informationsecurity news McDonald's

Post navigation

❮ Previous Post: BRUTE-FORCE ATTACKS TARGETING Citrix NetScaler UNDERWAY
Next Post: NINTH TELECOM COMPANY ADDED TO LIST OF Salt Typhoon TARGETS ❯

You may also like

News
SEVERITY UPGRADE for Log4Shell CVE-2021-45046
December 17, 2021
News
VULNERABILITIES FOUND IN ALL Nvidia GeForce GPUS
October 30, 2024
News
Microsoft Exchange CVE-2020-0688 – MULTIPLE EXPLOITS AVAILABLE
February 29, 2020
Cloud
AWS Log4Shell PATCH VULNERABLE TO CONTAINER ESCAPE AND PRIV ESCALATION
April 19, 2022

Recent Posts

  • Salt Typhoon THREAT ACTORS SPOTTED ON US GOVT NETWORKS BEFORE TELCOS
  • Charter and Windstream ADDED TO LIST OF TELCO PROVIDERS COMPROMISED BY Salt Typhoon
  • Cisco CONFIRMS AUTHENTICITY OF 4.45 GB DATA BREACH
  • NINTH TELECOM COMPANY ADDED TO LIST OF Salt Typhoon TARGETS
  • McDonald’s API EXPLOITED FOR ONE CENT DELIVERIES

Recent Comments

No comments to show.

Archives

  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • May 2024
  • April 2024
  • March 2024
  • September 2023
  • August 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • August 2022
  • July 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • September 2021
  • August 2021
  • July 2021
  • January 2021
  • December 2020
  • August 2020
  • May 2020
  • March 2020
  • February 2020
  • October 2019
  • June 2019
  • April 2019

Categories

  • Breach
  • Cloud
  • Conferences
  • Hardware Hacking
  • Malware
  • News
  • Ransomware
  • Tools
  • Tutorial
  • Uncategorized
  • Vulnerability
  • Walkthough
  • Home
  • Blog
  • CTF Cheat Sheet
  • About
  • Twitter
  • Github
  • YouTube

Copyright © 2025 bentoboxinfosec.

Theme: Oceanly News Dark by ScriptsTown