http://████/data.json showing users sensitive information via json file

Disclosed: 2019-12-02 20:05:31 By 00utsav00 To deptofdefense
Medium
Vulnerability Details
**Summary:** **Description:** hello DoD, here i am reporting an issue regarding information disclosure by direct URl access on publick facing webpage, please go to this link and analyses the json data. http://██████████/data.json ## Impact ## Step-by-step Reproduction Instructions 1. just go to this link http://███/data.json and you will get a sensitive information page within json format, please look at the screenshot poc ## Product, Version, and Configuration (If applicable) ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 184472
  • State: Closed
  • Substate: informative
  • Upvotes: 13
Share this report