PII Leak via /████████

Disclosed: 2021-02-18 19:10:51 By un4gi To deptofdefense
High
Vulnerability Details
**Summary:** An attacker is able to view PII (Full name/address/e-mail/phone) of all website users via █████████/████████ ## Step-by-step Reproduction Instructions 1. Browse to ████ and login or create an account. 2. Browse to ████/███████ 3. Begin typing a name in the `Select User` field, and click the `(i)` icon on the right side of the field to view the users data. ██████ ## Suggested Mitigation/Remediation Actions Restrict access to this endpoint to administrative roles. ## Impact An adversary can gather PII of all `█████████` users via this endpoint.
Actions
View on HackerOne
Report Stats
  • Report ID: 905679
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report