Bypassed a fix to gain access to PII of more than 100 Officers

Disclosed: 2021-02-10 21:11:28 By mrsinister15 To deptofdefense
Medium
Vulnerability Details
**Summary:** Hey team I hope this report finds you well and you're having a great day in these difficult times ;) While doing my Recon I have found out that https://www.███/ is leaking PII of many Officers Severity according to me- Critical ## Step-by-step Reproduction Instructions 1. Go to https://www.██████████ Not so easy ;) 2. It seems like this page contains the PII but you have patched it somehow... Here is how an attacker can Bypass that - ;) 3. Use this Google Dork- `█████████` 4. Now click on the cached content, and open it in a new tab ;) 5. There you go! Now the attacker can see the PII of too many Officers ;) POC: 1. Full POC- █████ ## Suggested Mitigation/Remediation Actions - Take it down if you can - Contact Google to take it down from the Cached content ## Impact PII Leakage Thanks, I hope you will manage to fix this soon ;) Regards, mrsinister15
Actions
View on HackerOne
Report Stats
  • Report ID: 1074136
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report