Firebase credentials leak

Disclosed: 2022-12-15 13:28:25 By jimmisimon To mtn_group
Unknown
Vulnerability Details
## Summary: This report is regarding the fix of #1351329. The fix is not patched fully, comments are visible to anyone and an attacker can utilize this for further attacks. ## Steps To Reproduce: go to : view-source:https://mpulse.mtn.ng/ search for 'Initialize Firebase' as you can see the firebase details are commented. ## Supporting Material/References: POC attached ## Impact Unauthorized access to firebase
Actions
View on HackerOne
Report Stats
  • Report ID: 1691888
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report