Enumerate class codes via yahoo dork - Can access any course under teacher - Sensitive information leaked
High
Vulnerability Details
Hello Team,
I am quality researcher and I found some links using yahoo dorking techniques
I used yahoo dork `site:pl.khanacademy.org/join`
I used Firefox browser.
Steps to reproduce:
1.Go to yahoo search page and use above query to enumerate.
2.Create student account by filling all the required details
3.Now you are in the class without actually invited by teacher.
4.You can pick any course from item and start you course.
I can also able to see teacher Full name- This is sensitive information
Attached POC:
## Impact
Any black hacker can enumerate all the classes and join in them and can make chaos.
Some chances of IDOR too.
If you can encrypt this class details which some hashing technique and this will not showed up with dorking queries.
Actions
View on HackerOneReport Stats
- Report ID: 1514356
- State: Closed
- Substate: resolved
- Upvotes: 16