Guide
Introduction
MP - FCIF - "MULTI - PAGE File Creation In Figma"
Figma Touts Its Collaborative Design Platform As Empowering Teams To Seamlessly Create And Iterate Designs. However, A Critical Vulnerability In Figma's Access Control Mechanisms Enables Starter Plan Users To Bypass Subscription Limitations. This Security Flaw Allows Starter Plan Users To Create An Unlimited Number Of Pages Within Collaborative Workspaces, Circumventing The Intended Restriction Of Only 3 Pages For Starter Plan Collaborative Files. This Unauthorized Page Creation Capability Represents A Significant Product Flaw That Undermines Figma's Intended Limitations And Pricing Model.
THE ASSET (the attack surface of the issue) — www.figma.com
WEAKNESS (the type of potential issue we have discovered) — A) Client-Side Enforcement of Server-Side Security (CWE-602) ; B) Improper Access Control - Generic (CWE-284) ; C) Business Logic Errors (CWE-840)
SEVERITY (estimate the severity of this issue) — CRITICAL
(go on POC to view how this bug works)