VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities
Two vulnerabilities were discovered in Golf Compete foreUP's REST API. The first vulnerability exposed merchant API credentials directly within customer record responses. These credentials, including username, password, and merchant ID, allowed any user to access the payment processor account. Furthermore, these credentials were identical for all customers at the same facility. The second vulnerability involved a missing object-level authorization check. This flaw, also known as Broken Object Level Authorization and Insecure Direct Object References, permitted users to retrieve any customer's full profile by altering the golfer_id in API requests. This included sensitive information like personal details, payment tokens, and transaction history. Combining both vulnerabilities, an attacker could obtain merchant credentials from any customer's record. With a single low-privilege customer account, one could access any customer's profile, stored payment tokens, and billing history. The shared web API meant all facilities using foreUP were affected. A customer from one facility could access merchant information from another. Thankfully, foreUP confirmed on July 26, 2026, that both vulnerabilities have been fixed. Users are advised to remain vigilant for phishing and identity theft.