Loading HuntDB...

Username disclosure at Main Domain

Low
S
Sifchain
Submitted None
Reported by dantt

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hello, PoC Link https://sifchain.finance//wp-json/wp/v2/users/ thanks. ## Impact Malicious counterpart could collect the usernames disclosed (and the admin user) and be focused throughout BF attack (as the usernames are now known), making it less harder to penetrate the data.gov systems.

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Information Disclosure