PII data Leakage through hackerone reports
Low
H
HackerOne
Submitted None
Actions:
Reported by
iamr0000t
Vulnerability Details
Technical details and impact analysis
##Summary:
I found PII data leakage through the HackerOne report. I found a link in one of the disclosed report that allow me to get the address and phone numbers of security researchers. Here I got the address and phone number of ████ (███)
Vulnerability Name: PII data Leakage through
##Steps to reproduce:
—>Just visit ███
—>You will find a link swag link there. (Refer: Screenshot 1)
—>Now visit the swag link ie. ██████████ and add a parameter there ██████████
—> link becomes : ████████
—>You will get the PII of researchers. (Refer: Screenshot 2)
##Fix
1.)████████ should be informed that the data might have leaked.
2.)Link should be redacted.
3.) When hackerone provides swag to researchers they should mention to keep the link strictly confidential ,
same information should also be provided to the programs on HackerOne , that offer swag.
## Impact
An attacker can get sensitive information about the other researchers like their addresses and phone number.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure