漏洞标题
Tabit - 过多的数据暴露
漏洞描述信息
Tabit - 过度的数据暴露
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
Tabit - Excessive data exposure
漏洞描述信息
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/management/{reservationId}?organization={orgId} API which returns a lot of data regarding the reservation (OWASP: API3): Name, mail, phone number, the number of visits of the user to this specific restaurant, the money he spent there, the money he spent on alcohol, whether he left a deposit etc. This information can easily be used for a phishing attack.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
N/A
漏洞标题
GTAB Software Tabit 安全漏洞
漏洞描述信息
GTAB Software Tabit是GTAB Software公司的一个用于创建、演奏和打印吉他、贝司或班卓琴指法谱的全功能程序。 GTAB Software Tabit 存在安全漏洞,该漏洞源于攻击者可以通过其URL映射的某个用于取消预订的页面端点修查询用户数据。比如用户的姓名、电子邮件地址和电话号码等。这可能被用于网络钓鱼攻击。
CVSS信息
N/A
漏洞类别
其他