Loading HuntDB...

User Information Disclosure via REST API

Low
O
ownCloud
Submitted None
Reported by 4websecurity

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hello, REST-API, allows anonymous access to functionality that allows a hacker to list all users who have published a post on a WordPress site. Unfortunately, this generally includes the admin account POC: https://owncloud.com/wp-json/wp/v2/users/ https://owncloud.com/wp-json/wp/v2/users/1/ Kind Regards, Alex.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure