Lucene search

K
huntrR0hansh315F5AC6-1B5E-4444-AD8F-802371DA3505
HistoryJan 02, 2022 - 8:29 p.m.

Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber

2022-01-0220:29:35
r0hansh
www.huntr.dev
7

0.004 Low

EPSS

Percentile

74.2%

Description

Any unauthorized/unauthenticated actor can find the PII data of all the users registered in the application.
PII - Personally Identifiable Information leaked by this application is first name, last name, email id, picture, username, is_admin status

Proof of Concept

1 Visit

https://demo.microweber.org/demo/api/users/search_authors

It shows you details of all the users

Impact

Attacker can grab this PII data and use it for any malicious purpose.

0.004 Low

EPSS

Percentile

74.2%

Related for 315F5AC6-1B5E-4444-AD8F-802371DA3505