critical information disclosure
Critical
Vulnerability Details
##Description:
hey all ,
I have found critical information through this endpoint /██████;
this endpoint contains all env vars used in a www.██████ such as server credentials, db ,mail , twitter client_id and client_secret , facebook client_id and client_secret, etc...
## Impact
full access control on every services on website
## System Host(s)
www.█████████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Go to
https://www.█████████/████████;
you need to put ; to bypass 401 error
## Suggested Mitigation/Remediation Actions
Actions
View on HackerOneReport Stats
- Report ID: 1106009
- State: Closed
- Substate: resolved
- Upvotes: 20