PII leakage-Full SSN on ███

Disclosed: 2019-10-10 19:14:46 By alyssa_herrera To deptofdefense
Critical
Vulnerability Details
**Summary:** I discovered a pdf file on ████████ that outlines various information corresponding to military members. It reveals information on date of birth, where they were born, marriage status, race, children/dependents, etc **Description:** I discovered what looks to be an internal file that outlines sensitive information on various service member and looks to be publicly accessible ## Impact High ## Step-by-step Reproduction Instructions Visit: https://█████/wp-content/uploads/2018/12/██████████ ## Product, Version, and Configuration (If applicable) N/A ## Suggested Mitigation/Remediation Actions Remove immedietly ## Impact An attacker can gleam highly personal information on military members.
Actions
View on HackerOne
Report Stats
  • Report ID: 644358
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report