Skip to content

Latest commit

 

History

History
21 lines (14 loc) · 913 Bytes

2024-12-16.md

File metadata and controls

21 lines (14 loc) · 913 Bytes

Dec-16-2024 - Leaked email addresses from specific studio

Reported on Immunefi Dec-16-2024
Mitigation Dec-16-2024
Solution Completed Dec-16-2024

Description

When browsing to the review verification page the API returns metadata of this review including the e-mail address of the author. When accessing to a studio profile page the API return the list of review IDs related to this studio. Using this IDs, is possible to reach the verification url of each review and see the e-mail address of the authors.

Severity

Websites & Applications - Low.

Solution

Both endpoints has been modified to not expose sensitive information not needed for rendering each webpage. Verification url doesn't expose e-mail address anymore. Studios profile pages doesn't expose reviews IDs