Number, username and name disclosure

Disclosed: 2015-03-04 14:30:45 By 4lemon To mobilevikings
Unknown
Vulnerability Details
when user request a new card he can input some viking's number as a referrer and in order review page he can see viking's username When he add authorization to his own sim, he can use not only email but username and as a result he can get full vikings name in auth list. See attach.
Actions
View on HackerOne
Report Stats
  • Report ID: 45243
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report