Smartsheet employees email disclosure through enpoint after login.

Disclosed: 2020-09-09 22:15:47 By soareswallace To smartsheet
Low
Vulnerability Details
## Summary: [add summary of the vulnerability] After login - while validating this issue [#858974](https://hackerone.com/reports/858974) - I notice there is an endpoint call `/b/home?formName=webop&formAction=SheetLabLoadData&to=68000&ss_v=98.0.2` that is bringing emails from some employees. ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. Login with your account 2. While tracking traffic with your favorite traffic tracker capture the endpoint mentioned in the summary. 3. Check the response I honestly search in the dashboard where this information could be used and didn't founded it. Do we need this endpoint call? ## Bug Behavior Expected: Do we need this information while loading the dashboard? Actual: Employees email and name are being disclosed in the response ## Supporting Material/References: [#858974](https://hackerone.com/reports/858974) ## Impact Unnecessarily disclosing employee emails via endpoint call.
Actions
View on HackerOne
Report Stats
  • Report ID: 880089
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report