A security researcher disclosed multiple vulnerabilities in Yahoo's Small Business/Luminate platform that allowed access to sensitive customer and internal infrastructure data. In one case, a directory traversal flaw across invoice, subscription, order, and payment-related endpoints let an attacker browse files in user-specific directories by abusing ../ path sequences and predictable account identifiers derived from a victim's email address. By chaining that weakness with a cart modification endpoint that leaked a payment token after brute-forcing a guessable subscription number, the researcher said an attacker with only an email address could retrieve billing details including the last four digits of a credit card, expiration month, and billing address.
In a separate finding on the same platform, the researcher exploited a server-side request forgery in a screenshot feature after discovering an exposed config.json file that referenced a Yahoo proxy to internal domains. The flaw enabled enumeration of internal hosts tied to Chef, Docker, AWS-related systems, Graylog, and MongoDB, and was combined with an XSS issue in the site editor to force the screenshot service to fetch attacker-controlled URLs, including the AWS metadata address 169.254.169.254. The researcher reported the issues to Yahoo, said testing stopped after impact was confirmed, and noted that Yahoo remediated the SSRF and XSS in August 2017 and the directory traversal chain in November 2017.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Yahoo remediated the directory traversal vulnerability chain affecting invoice, subscription, order, and payment-method related functionality on its Small Business platform.
Yahoo acknowledged and triaged the directory traversal and billing-data exposure report two days after it was submitted.
A security researcher disclosed a directory traversal vulnerability chain in Yahoo's Small Business platform on luminate.com that exposed customer billing and payment-related information. By combining traversal flaws with a cart modification endpoint and guessable subscription numbers, an attacker with a victim's email address could access payment method details such as last four digits, expiration month, and billing address.
Yahoo fixed the related XSS issue in the site editor that had been used to help exploit the SSRF path.
Yahoo remediated the SSRF issue in the Small Business/Luminate platform's screenshot-related functionality.
Yahoo acknowledged and triaged the reported SSRF and XSS vulnerabilities on the same day they were submitted.
A security researcher identified an SSRF vulnerability in Yahoo's Small Business/Luminate platform, chained with an XSS issue in the site editor, that enabled requests to internal services including AWS metadata and other internal hosts. The researcher reported the issue to Yahoo and stopped further testing after confirming the impact.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
samcurry.net
Open sourcesamcurry.net
Open sourceseanmelia.files.wordpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.