Publicly accessible Order confirmations leaking User Emails on ███

Disclosed: 2019-10-08 18:55:41 By alyssa_herrera To deptofdefense
High
Vulnerability Details
**Summary:** I noticed that a user's order confirmation was publicly accessible leaking email information **Description:** An attacker can gleam sensitive information that is stored in the order confirmation file ## Impact Medium ## Step-by-step Reproduction Instructions https://██████████/BinaryHandler.ashx?RecordID=MZtO1v39KiFWXykCvQEcOw%3D%3D ## Product, Version, and Configuration (If applicable) N/A ## Suggested Mitigation/Remediation Actions Scrub user data ## Impact Attackers can steal PII
Actions
View on HackerOne
Report Stats
  • Report ID: 323992
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report