SEGUC17 / Foobar

1 stars 0 forks source link

accessing all details of any user making announcement #62

Closed mmenbawy closed 7 years ago

mmenbawy commented 7 years ago

1: Severity: ( high )

2:Reported: By Mostafa

3:Description: all details of service providers or admins who made announcements including login details and private info

4: Steps to reproduce the issue: send a get request to http://54.77.11.251:3000/api/announcements/view login, announcements, inspect the code, networks, view

5: Expected result: - screenshot 21

amr3mmar commented 7 years ago

We should fix it