Loading HuntDB...

PII data Leakage through hackerone reports

Low
H
HackerOne
Submitted None
Reported by iamr0000t

Vulnerability Details

Technical details and impact analysis

Information Disclosure
##Summary: I found PII data leakage through the HackerOne report. I found a link in one of the disclosed report that allow me to get the address and phone numbers of security researchers. Here I got the address and phone number of ████ (███) Vulnerability Name: PII data Leakage through ##Steps to reproduce: —>Just visit ███ —>You will find a link swag link there. (Refer: Screenshot 1) —>Now visit the swag link ie. ██████████ and add a parameter there ██████████ —> link becomes : ████████ —>You will get the PII of researchers. (Refer: Screenshot 2) ##Fix 1.)████████ should be informed that the data might have leaked. 2.)Link should be redacted. 3.) When hackerone provides swag to researchers they should mention to keep the link strictly confidential , same information should also be provided to the programs on HackerOne , that offer swag. ## Impact An attacker can get sensitive information about the other researchers like their addresses and phone number.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure