BREAKING
AI Finds SQL Flaw in FGT Ticketing
How the Attack Worked
Entry Point
deviceUID
●
Unauthenticated SQL injection
●
At fgtapi.frontgatetickets.com
Claude's Role
autonomous
●
Generated nested queries
●
Bypassed the WAF
From Injection to Super-Admin
1
SQL injection
↓
2
Read fgs database
↓
3
Reset token
↓
4
Super-admin access
0
+
database tables
0
$
Platinum pass value
0
h
fix time
No Tickets Issued, Flaw Reported
AI Cuts Both Ways in Security
AI NEWS BLITZ
A researcher used Anthropic's Claude to uncover a critical flaw in a major ticketing platform.