Username disclosure at Main Domain
Low
S
Sifchain
Submitted None
Actions:
Reported by
dantt
Vulnerability Details
Technical details and impact analysis
Hello,
PoC Link
https://sifchain.finance//wp-json/wp/v2/users/
thanks.
## Impact
Malicious counterpart could collect the usernames disclosed (and the admin user) and be focused throughout BF attack (as the usernames are now known), making it less harder to penetrate the data.gov systems.
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate
Submitted
Weakness
Information Disclosure