Insecure API Response Leads to Disclosure of Hashed Passwords
Medium
M
Mars
Submitted None
Team Summary
Official summary from Mars
A security vulnerability has been identified in the API of ████████. The endpoint ████████ is found to return sensitive user information, including hashed passwords, in its response. This exposure presents a significant security risk as it potentially allows unauthorized access to user credentials. The vulnerability is further exacerbated by the use of sequential numerical IDs, which makes user accounts susceptible to enumeration attacks.
Actions:
Reported by
itsmatinx
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure