Loading HuntDB...

DoD internal documents are leaked to the public

Medium
U
U.S. Dept Of Defense
Submitted None
Reported by mrempy

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hello Team, I found a zip file containing documents about DoD. From what I looked at are documents for new soldiers who are starting out, but I didn't just find these files but several others like advice, commander files, plans, certificates and others. ███ ██████ █████████ In some of the files I found information such as name, surname, email, phone number and even signatures. Files like these shouldn't be exposed to the public. ██████████ █████████ █████ █████ Here is a list of the folders and documents that exist inside this zip file (it's quite big): █████ ## Impact * Anyone can download these files and leak them to the public * Plan something against a specific person for a crime ## System Host(s) ████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce 1. Open in your browser the URL https://█████ 2. Look for the file called "████" and download it 3. Extract the file and look at the documents I found some certificates in the Formats folder, in the Welcome folder there is someone's phone number, command files are in the Commander Files folder. ## Suggested Mitigation/Remediation Actions * Change the location of this zip file and the others * Block viewing of files in this folder

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure