#9 Account enumeration

Suljettu
5 vuotta sitten avasi sindre · 1 kommenttia

An adversary can view all registered users when applying for aproject.

An adversary can view all registered users when applying for aproject.
sindre added this to the Required fixes milestone 5 vuotta sitten
sindre added the
sensitive data exposure
label 5 vuotta sitten
sindre added the
bug
label 5 vuotta sitten
sindre added the
webpy
label 5 vuotta sitten
sindre commented 5 vuotta sitten
Omistaja

This can be done by allowing any username, and not indicating whether the user exists or not.

This can be done by allowing any username, and not indicating whether the user exists or not.
Sign in to join this conversation.
Loading…
Peruuta
Tallenna
Sisältöä ei vielä ole.