Loading HuntDB...

Duplicate Entry of email leads to 500 Server Error which disclosing the SQL Database table information

Critical
K
Kartpay
Submitted None

Team Summary

Official summary from Kartpay

The Issue was with the process of Deletion of the merchant data from the admin Dashboard. The Admin has rights to delete the merchant email ID and further, it gets deleted as Soft delete, not the full delete but there was no Validation to the codes which can detect the re-registration of the same Email ID which leads to the Critical error. Secondly, it was found that while pushing the codes in the production, The Debug was enabled and show the data only needed for internal use.

Reported by basant0x01

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure