New API < v0.12.10 contains a broken authentication caused by unauthenticated attacker forging Stripe webhook events, letting attackers credit arbitrary quota without payment, exploit requires no authentication.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view