Skip to content

Latest commit

Β 

History

8 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 

Repository files navigation

πŸ›‘οΈ API Broken Access Control & PII Exposure: Government Complaint Support System (CSS)

Ministry of Interior β€” Cambodia

Target Vuln CVSS Status Disclosure


πŸ“‹ Executive Summary

This case study documents the discovery, responsible disclosure, and successful remediation of a Broken Access Control vulnerability in a live government API handling citizen complaint records. The flaw allowed any unauthenticated actor to issue bulk HTTP GET requests against the /api/v1/complaints collection endpoint and receive structured PII for over 1,000+ citizen entries including full names, phone numbers, and sensitive allegation descriptions.

The root cause was a Default Allow posture inherited from the public submission flow β€” the API correctly permitted anonymous POST requests for citizen submissions but failed to restrict GET access at the method level, exposing the entire complaints collection to unauthenticated reads.

Responsibly disclosed to MOI IT stakeholders. Patch verified February 19, 2026.


🎯 Target Profile

Field Detail
System Government Complaint Support System (CSS)
API Stack Spring Boot, Spring Security
Endpoint /api/v1/complaints
Method HTTP GET (unauthenticated)
Data Exposed Citizen PII β€” names, phone numbers, complaint descriptions
Records Exposed 1,000+ entries

πŸ—ΊοΈ Vulnerability Flow

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚               CSS API ACCESS CONTROL FLAW                    β”‚
β”‚                                                              β”‚
β”‚  [Citizen]  ──POST──▢  /api/v1/complaints  βœ… permitAll()   β”‚
β”‚                                β”‚                             β”‚
β”‚  [Attacker] ──GET───▢  /api/v1/complaints  ❌ no restriction β”‚
β”‚                                β”‚                             β”‚
β”‚                                β–Ό                             β”‚
β”‚              Full JSON dump of 1,000+ PII records            β”‚
β”‚              { name, phone, description, status }            β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ”¬ Methodology

Phase 1 β€” Reconnaissance

Deployed Bubble-Scanner to map the Spring Boot API surface. The tool's Bubble-Dive Engine recursively fuzzes endpoints and triggers sub-scanners on every 200 OK response, including:

  • Source code scavenging (regex patterns for leaked API keys, tokens, hardcoded credentials)
  • RCE vector identification (file upload forms, unvalidated input fields)
  • Basic error-based SQLi probing on discovered parameters
bubble_dive() {
    head -n 1000 "$WORDLIST" | while read -r path; do
        url="${base_url%/}/${path}"
        res=$(curl -s -o /dev/null -w "%{http_code}" "$url")
        if [ "$res" == "200" ]; then
            scan_source_code "$url"   # hunt for leaked secrets
            check_upload_vuln "$url"  # identify RCE vectors
        fi
    done
}

Phase 2 β€” Traffic Analysis

Observed a discrepancy between the authenticated admin dashboard (correctly access-controlled) and the raw API routes beneath it. The frontend enforced auth; the backend did not.

Phase 3 β€” Vulnerability Confirmation

Unauthenticated GET to the complaints collection returned a full database dump instead of the expected 403 Forbidden:

# Unauthenticated collection probe (pre-patch)
curl -i -k 'https://[TARGET_REDACTED]/api/v1/complaints'

Response (anonymized sample):

[
  {
    "id": 7,
    "plaintiffName": "αž αž»αž„ [REDACTED]",
    "phoneNumber": "086******",
    "description": "Sensitive allegation description...",
    "status": "PENDING"
  }
]

Phase 4 β€” Disclosure & Remediation

Delivered a Root Cause Analysis to MOI IT stakeholders identifying the missing method-level security configuration. The recommended fix:

// Spring Security fix (conceptual β€” applied by MOI IT team)
.requestMatchers(HttpMethod.POST, "/api/v1/complaints").permitAll()  // public submissions
.requestMatchers(HttpMethod.GET,  "/api/v1/complaints").hasRole("ADMIN")  // restrict reads

Phase 5 β€” Patch Verification

Regression tested all previously successful extraction vectors on February 19, 2026. All endpoints returned HTTP 403 Forbidden for unauthenticated GET requests. Public POST submission flow remained functional.


πŸ” Vulnerability Analysis

CWE Classification

CWE Description
CWE-284 Improper Access Control
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-285 Improper Authorization (method-level GET/POST distinction missing)

CVSS v3.1 Scoring

Score: 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Metric Value Rationale
Attack Vector Network Exploitable remotely over HTTP
Attack Complexity Low Single unauthenticated GET request
Privileges Required None No auth token needed
User Interaction None Fully automated extraction possible
Confidentiality High Full PII collection exposed
Integrity None Read-only β€” no write access demonstrated
Availability None No service disruption

πŸŽ–οΈ Outcome

Metric Result
Discovery date February 2026
Report submitted February 18, 2026
Patch verified February 19, 2026
Time to remediation < 24 hours
Disclosure type Responsible β€” coordinated with MOI IT
PII records secured 1,000+ entries

πŸ› οΈ Tools Used

Tool Purpose
Bubble-Scanner Endpoint discovery, source recon, SQLi probing
curl Manual endpoint probing & verification
Spring Security docs Remediation guidance

Disclaimer: This research was conducted for educational and security-hardening purposes. No data was retained or exfiltrated. All findings were reported directly to the system owner prior to publication.


πŸ‘€ Author

MoriartyPuth β€” Offensive Security

GitHub

⚠️ Disclaimer. This document is a sanitised portfolio artefact produced from an authorised penetration test. All identifying data has been redacted or replaced with documentation-reserved placeholders. It contains no client data, no live targets and no novel exploit code. Techniques shown are standard, publicly documented, and provided for educational and defensive purposes only. Do not test any system you do not own or lack explicit written authorisation to assess.


About

API Broken Access Control & PII Remediation

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors