Project

General

Profile

Actions

Bug #75

closed

Feature #65: Security Audit

[Security Audit ]10 -Sensitive Information Disclosure

Added by Kalyan Battula about 1 year ago. Updated 7 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Deepika Valluri
Category:
-
Target version:
Start date:
17/04/2024
Due date:
% Done:

0%

Estimated time:
Deployed In:
Category:

Description

10- Sensitive Information Disclosure

CWE : CEW-200
Description :
Information disclosure, also known as information leakage, is when a website
unintentionally reveals sensitive information to its users. Depending on the context,
websites may leak all kinds of information to a potential attacker, including: (a) Data
about other users, such as usernames or financial information (b) Sensitive commercial
or business data (c) Technical details about the website and its infrastructure
Affected Path(s) :
https://earogya.satragroup.in/patient/search-update-patient *-Applicable to entire
application
Impact :
The dangers of leaking sensitive user or business data are fairly obvious, but disclosing
technical information can sometimes be just as serious. Although some of this
information will be of limited use, it can potentially be a starting point for exposing an
additional attack surface, which may contain other interesting vulnerabilities.
Recommendation :
It is recommended not to disclose any sensitive information to the end user. Incase of
aadhaar: It is recommended to use Aadhaar vault service to store aadhaar numbers
securely as per UIDAI guidelines. Mask Aadhaar numbers and display only last 4 digits.
Evidence/Proof Of Concept :
Step 1: Access the URL "https://earogya.satragroup.in/patient/search-update-patient" and
it was observed that sensitive information like "Aadhar numbers" were disclosed in Plain text
as shown in below screenshot.


Files

clipboard-202404171545-ca3dd.png (62.6 KB) clipboard-202404171545-ca3dd.png Kalyan Battula, 17/04/2024 03:45 PM
Actions #1

Updated by Deepika Valluri 12 months ago

  • Status changed from New to In Progress
  • Assignee set to Deepika Valluri
Actions #2

Updated by Karthik Daram 12 months ago

  • Status changed from In Progress to Resolved
Actions #3

Updated by Sivakanth Kesiraju 12 months ago

  • Target version set to Sprint 1 (29th April - 3rd May)
Actions #4

Updated by Sivakanth Kesiraju 12 months ago

  • Target version changed from Sprint 1 (29th April - 3rd May) to Security Audit
Actions #5

Updated by Gautam Kumar 7 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF