Loading HuntDB...

User Information sent to client through websockets

L
Legal Robot
Submitted None
Reported by cablej

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hey, I noticed when monitoring the websocket requests that the account information of many users, including email address, is sent to the client. For example: ``` ██████ ██████████ █████████ ████████ ███████ ``` There's hundreds of these requests, each containing user information. Please let me know if this is meant to be happening, but I didn't see a list of users on the site.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure