Duplicate Entry of email leads to 500 Server Error which disclosing the SQL Database table information
Critical
K
Kartpay
Submitted None
Team Summary
Official summary from Kartpay
The Issue was with the process of Deletion of the merchant data from the admin Dashboard. The Admin has rights to delete the merchant email ID and further, it gets deleted as Soft delete, not the full delete but there was no Validation to the codes which can detect the re-registration of the same Email ID which leads to the Critical error. Secondly, it was found that while pushing the codes in the production, The Debug was enabled and show the data only needed for internal use.
Actions:
Reported by
basant0x01
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure