Mars: Insecure API Response Leads to Disclosure of Hashed Passwords
Discription

A security vulnerability was identified in the API of ████████. The endpoint ████████ was found to return sensitive user information, including hashed passwords, in its response. This exposure presented a significant security risk, as it potentially allowed unauthorized access to user credentials. The vulnerability was further exacerbated by the use of sequential numerical IDs, which made user accounts susceptible to enumeration…Read More
References
Back to Main