Research use only. Test against your own account.
Demonstrates that paddle_session_vendor is the sole auth token on vendors.paddle.com/dashboard/api/userinfo with no IP/UA/device binding.
paddle_session_vendor
vendors.paddle.com/dashboard/api/userinfo
pip install requests rich
python exploit.py
See report.md for full vulnerability writeup.