Publicly accessible Order confirmations leaking User Emails on ███
High
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
alyssa_herrera
Vulnerability Details
Technical details and impact analysis
**Summary:**
I noticed that a user's order confirmation was publicly accessible leaking email information
**Description:**
An attacker can gleam sensitive information that is stored in the order confirmation file
## Impact
Medium
## Step-by-step Reproduction Instructions
https://██████████/BinaryHandler.ashx?RecordID=MZtO1v39KiFWXykCvQEcOw%3D%3D
## Product, Version, and Configuration (If applicable)
N/A
## Suggested Mitigation/Remediation Actions
Scrub user data
## Impact
Attackers can steal PII
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure