Loading HuntDB...

█.8x8.vc/index.js: Exposed Google Maps API Key Allowing Potential Abuse of Paid Services

Medium
8
8x8 Bounty
Submitted None

Team Summary

Official summary from 8x8 Bounty

We resolved an issue where a Google Maps API key allowed potential unauthorized access to some Google Maps services. While the API key was intentionally included in client-side code, it lacked proper restrictions to prevent abuse of paid services. The potential impact could theoretically lead to API quota consumption and related billing concerns, though actual impact was limited as no evidence of exploitation was found. Our team promptly validated and addressed the report by implementing appropriate API key restrictions where feasible, while accepting other known limitations.

Reported by abdallasamir12

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Information Disclosure