Server responds with the server error logs on account creation

Disclosed: 2015-11-26 20:49:08 By tmfelwu To enter
Unknown
Vulnerability Details
**Impact** Poorly protected response can provide a gold mine of information to an attacker, disclosing a host of sensitive information such as function and file names. This information may enable the attacker to immediately or later compromise the entire application. **PoC** 1. Create a new wallet. 2. Intercept the request using a proxy tool. 3. Edit the `bankAccountType` to anything other than CHECKING The server responds with error log of the server in the header of the response, see attached picture. Thanks crab
Actions
View on HackerOne
Report Stats
  • Report ID: 57692
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report