logo

Database

Description

It is possible to list information and login method of the platform users, since a token associated to the account is not used to consult the information, thus leaving open the possibility to consult information of other users.

Impact

- Identify users login method. - Obtain strategic information. from users accounts.

Recommendation

Implement controls with cookies or session tokens to limit the information viewed by a user.

Threat

Authenticated attacker from the Internet.

Expected Remediation Time

⏱️ 60 minutes.