Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

EDIT: removing URLs because it's the right thing to do.


Click on 'current usage' in your account and it takes you to your current invoice, which is accessible via the URL that he mentions. It appears to be only the current months usage / invoice that is vulnerable.


EDIT: removing URLs because it's the right thing to do.


Yikes - so are past invoices available as well then via the show/:id url?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: