Excessive Data Exposure
What is Excessive Data Exposure:
GET /api/v1/info?email=John312@gmail.com
Host: api.target.comHTTP/1.1 200 OK
Content-Type: application/json
{
"id" : 252,
"first_name" : "John",
"last_name" : "",
"email" : "John312@gmail.com",
"phone" : "30215928123",
"privilege" : "user",
"representative" : [
"id" : 122,
"first_name" : "Sarah",
"last_name" : "Yasser",
"email" : "SarahY222@gmail.com",
"phone" : "1248228122",
"privilege" : "admin",
"2fa" : false
]
}How to hunt for it:

Resources about the vulnerability:
Last updated