User Information sent to client through websockets
L
Legal Robot
Submitted None
Actions:
Reported by
cablej
Vulnerability Details
Technical details and impact analysis
Hey,
I noticed when monitoring the websocket requests that the account information of many users, including email address, is sent to the client. For example:
```
██████
██████████
█████████
████████
███████
```
There's hundreds of these requests, each containing user information. Please let me know if this is meant to be happening, but I didn't see a list of users on the site.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure