Improper authentication in the load sell inventory page

Disclosed: 2020-10-08 09:39:17 By niggy To cs_money
Unknown
Vulnerability Details
## Summary: Hello team, I found an endpoint response all data relate to sell mode inventory that doesn't have improper authentication in the link: https://cs.money/load_sell_mode_inventory ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. Open directly the link: https://cs.money/load_sell_mode_inventory 2. Observe the result ## Supporting Material/References: * [attachment / reference] ## Impact All most data in the site to view then user have to login the first. I think that you are missing authentication for these pages.
Actions
View on HackerOne
Report Stats
  • Report ID: 993767
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report