critical information disclosure

Disclosed: 2021-03-11 21:27:08 By ba56adcb299ff13a87475bf To deptofdefense
Critical
Vulnerability Details
##Description: hey all , I have found critical information through this endpoint /██████; this endpoint contains all env vars used in a www.██████ such as server credentials, db ,mail , twitter client_id and client_secret , facebook client_id and client_secret, etc... ## Impact full access control on every services on website ## System Host(s) www.█████████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Go to https://www.█████████/████████; you need to put ; to bypass 401 error ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1106009
  • State: Closed
  • Substate: resolved
  • Upvotes: 20
Share this report