Leaking usernames through endpoints Wordpress
High
Vulnerability Details
## Summary:
Hi first, some of my usernames have been leaked by endpoints https://alt.mtn.com/wp-json/wp/v2/users
## Steps To Reproduce:
[The steps are as follows]
1. Open the subdomain https://alt.mtn.com
1. Add the path https://alt.mtn.com/wp-json/wp/v2/users/192
1. [You will notice the user information and you can also reveal many user names by changing it id user As in the pictures ]
{F2050805}
{F2050804}
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
#1735586
#356047
## Impact
by API The attacker can find many information and names of active users
Actions
View on HackerOneReport Stats
- Report ID: 1785021
- State: Closed
- Substate: resolved
- Upvotes: 27