Shady Oaks Finance
Daily · 5 writeupsA recurring daily challenge — each entry covers a different vulnerability. Listed oldest to newest.
BugForge - Daily - Shady Oaks Finance (Jan 2, 2026)
This vulnerability is a broken access control issue caused by insecure design, where the application trusts client-supplied input to set sensitive user…
BugForge - Daily - Shady Oaks Finance (Jan 9, 2026)
This challenge demonstrates a JWT (JSON Web Token) authentication bypass vulnerability caused by improper algorithm validation. The application accepts…
BugForge - Daily - Shady Oaks Finance (Jan 16, 2026)
Broken access control was identified where administrative endpoints were exposed without proper server-side authorization checks. By enumerating…
BugForge - Daily - Shady Oaks Finance (Jan 23, 2026)
This challenge demonstrates a race condition vulnerability in a currency exchange endpoint where balance verification and balance deduction are not performed…
BugForge - Daily - Shady Oaks Finance (Jul 12, 2026)
The Shady Oaks forecasting feature renders the user-supplied caption through a server-side template engine, so injecting {api_key} leaks the secret straight back in the response.