-
Notifications
You must be signed in to change notification settings - Fork 788
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[TODO] Data leak by enumeration #820
Comments
He, big thanks, this is indeed something that should be fixed... I'm a little bit unsure if it's the better option to touch the project again or simply leave it, as the script has reached "end of life" some time ago... @ALL What do the others think ? |
About point 1 Also changing it so that the url doesn't have the ID number in it does not remove the threat of enumeration as one can just enumerate using post requests. To fix this would require making IDs random (probably include alpha numberic). About point 2 Imagine you go to reset your password and mistype your email just slightly and the site says your email was sent then you goto your email and never receive an email. |
Hello guys, very nice project! Here are two problems I noticed:
The text was updated successfully, but these errors were encountered: