HackVitraSec - Cybersecurity Company India | VAPT, Ethical Hacking, Web App Security

Case Study: OAuth Token Bypass in Healthcare Portal

Client Type: Health SaaS Platform | Engagement: API Pentest | Date: July 2025

Background

A healthcare management platform (HMS) storing medical records, prescriptions, and reports for 50+ hospitals onboarded HackVitraSec for a comprehensive API VAPT.

Vulnerability Details

Our team found a critical OAuth token validation flaw. A previously generated access token from a different user account could be reused to fetch other users' medical records.

The backend failed to verify the audience and scope of the token before allowing access to protected resources.

Impact

Exploitation

Using Burp Suite and Postman, the team replayed a valid token with minor header changes to access unauthorized records. Proof-of-concept demonstrated live data leaks.

Remediation

Lessons Learned

Need an API Security Audit?

Contact HackVitraSec Today →