Loading HuntDB...

IRC-Bot exposes information

Medium
P
Phabricator
Submitted None
Reported by luke081515

Vulnerability Details

Technical details and impact analysis

Information Disclosure
You can setup the IRC-Bot, and set it into private channels, so that it posts only information about tasks into private channels. Example: <Human> T698 <Bot> T698: Task title - https://url.example.org/T698 The problem is, that, if the bot is online in IRC, you can send him task numbers via private messages, and then he exposes the title of tasks without access control.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure