SEGUC17 / Foobar

1 stars 0 forks source link

Admins' credentials #49

Open mmenbawy opened 7 years ago

mmenbawy commented 7 years ago

1: Severity: ( HIGH )

2:Reported: By Mostafa

3:Description: By going to /api/announcements/view I can view a full list of the website's admins and their login information

4: Steps to reproduce the issue: Go to the URL "http://54.77.11.251:3000/api/announcements/view"

5: Expected result: This endpoint should not respond with such information

mahmoud-adel-mahmoud commented 7 years ago
screen shot 2017-05-01 at 8 02 31 pm