#9 Account enumeration

Closed
opened 5 years ago by sindre · 1 comments
sindre commented 5 years ago

An adversary can view all registered users when applying for aproject.

An adversary can view all registered users when applying for aproject.
sindre added this to the Required fixes milestone 5 years ago
sindre added the
sensitive data exposure
label 5 years ago
sindre added the
bug
label 5 years ago
sindre added the
webpy
label 5 years ago
sindre commented 5 years ago
Owner

This can be done by allowing any username, and not indicating whether the user exists or not.

This can be done by allowing any username, and not indicating whether the user exists or not.
Sign in to join this conversation.
Loading…
Cancel
Save
There is no content yet.