Site icon API Security Blog

WakaTime: User Email Disclosure via ID-Based Invitation

image
The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the privacy settings and led to unintended email…Read More

Exit mobile version