> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Cas Allegedly is Selling an IDOR Vulnerability in Al-Rajhi Bank APIs
- URL: https://darkwebinformer.com/cas-allegedly-is-selling-an-idor-vulnerability-in-al-rajhi-bank-apis/
- Published: 2024-09-29T00:31:46.000Z
- Updated: 2025-09-04T22:26:19.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

🔗 DarkWebInformer.com:  
📅 Date: 2024-09-29 01:27:39  
🚨 Title: Alleged sale of IDOR vulnerability in Al-Rajhi Bank APIs  
🛡️ Victim Country: Saudi Arabia  
🏭 Victim Industry: Financial Services  
🏢 Victim Organization: al-rajhi bank  
🌐 Victim Site: alrajhibank.com.sa  
📜 Category: Vulnerability  
🔗 Claim: <https://breachforums.st/Thread-SELLING-IDOR-in-AlrajhiBanks-APIs>  
🕵️‍♂️ Threat Actor: Cas  
🌍 Network: openweb  
📝 Description: Threat actor claims to be selling an IDOR (Insecure Direct Object Reference) vulnerability in Al-Rajhi Bank APIs. Threat actor also claims that the vulnerability allows unauthorized access to sensitive data, including user carts, and could potentially include other exploits, such as NoSQL injection.  
Screenshots:

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/09/image-284.png)