connect.8x8.com: Users with no permission can track/access restricted details/data via GET /api/v2/support/requests/<ticket number >HTTP/2

Disclosed: 2023-02-15 08:00:57 By emperor To 8x8-bounty
High
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 1499114
  • State: Closed
  • Substate: resolved
  • Upvotes: 29
Share this report