Loading HuntDB...

Usernames ending in .json are not restricted

G
Gratipay
Submitted None
Reported by karthic

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Desciption: Username in *.json is not restricted. disallowed *.json is allowed in username restriction URL : https://gratipay.com/robots.txt User-agent: * Disallow: /*.json Disallow: /on/* POC URL: https://gratipay.com/~karthic.json/ and you will end up at my profile page.

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Violation of Secure Design Principles