Leaking usernames through endpoints Wordpress

Disclosed: 2024-08-10 01:20:23 By alitoni224 To mtn_group
High
Vulnerability Details
## Summary: Hi first, some of my usernames have been leaked by endpoints https://alt.mtn.com/wp-json/wp/v2/users ## Steps To Reproduce: [The steps are as follows] 1. Open the subdomain https://alt.mtn.com 1. Add the path https://alt.mtn.com/wp-json/wp/v2/users/192 1. [You will notice the user information and you can also reveal many user names by changing it id user As in the pictures ] {F2050805} {F2050804} ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] #1735586 #356047 ## Impact by API The attacker can find many information and names of active users
Actions
View on HackerOne
Report Stats
  • Report ID: 1785021
  • State: Closed
  • Substate: resolved
  • Upvotes: 27
Share this report