https://www.legalrobot.com/

Disclosed: 2018-03-14 15:50:55 By caesar302 To legalrobot
Unknown
Vulnerability Details
Hello, I found a info disclosure vulnerability. We can enumerate emails via user_id parameter from Manage users. And I found that : [email protected] [email protected] [email protected] [email protected] [email protected] I attached photos from burp repeater to be more explicit. We can easily bruteforce user_id parameter with ids to harvest user's emails. Regards,
Actions
View on HackerOne
Report Stats
  • Report ID: 228156
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 1
Share this report