Project

General

Profile

Actions

Bug #88

closed

Feature #65: Security Audit

[Security Audit ] 23- Email addresses disclosed

Added by Kalyan Battula about 1 year ago. Updated 7 months ago.

Status:
Closed
Priority:
Low
Category:
-
Target version:
Start date:
17/04/2024
Due date:
% Done:

0%

Estimated time:
Deployed In:
Category:

Description

23 -Email addresses disclosed
CWE : CWE-200
Description :
email addresses of developers and other individuals (whether appearing on-screen or
hidden within page source) may disclose information that is useful to an attacker; for
example, they may represent usernames that can be used at the application's login, and
they may be used in social engineering attacks against the organization's personnel.
Affected Path(s) :
https://earogya.satragroup.in/privacy-policy *-Applicable to entire application
Impact :
Unnecessary or excessive disclosure of email addresses may lead to social engineering
attacks and increase in the volume of spam email received.
Recommendation :
1. Consider removing any email addresses that are unnecessary, or replacing
personal addresses with anonymous mailbox addresses (such as
).
2. Obfuscate the email addresses in such as way that
displayed as emailaddress[at]something[dot]com.
3. To reduce the quantity of spam sent to anonymous mailbox addresses, consider
hiding the email address and instead providing a form that generates the email
server-side, protected by a CAPTCHA if necessary.
Evidence/Proof Of Concept :
Step 1: Email addresses disclosed as shown in below screenshot.


Files

clipboard-202404171606-3c4ii.png (129 KB) clipboard-202404171606-3c4ii.png Kalyan Battula, 17/04/2024 04:06 PM
Actions #1

Updated by Deepika Valluri 12 months ago

  • Status changed from New to In Progress
  • Assignee set to Deepika Valluri
Actions #2

Updated by Uma Maheswarachari Melpati 12 months ago

  • Assignee changed from Deepika Valluri to Uma Maheswarachari Melpati
Actions #3

Updated by Uma Maheswarachari Melpati 12 months ago

  • Status changed from In Progress to Resolved
Actions #4

Updated by Sivakanth Kesiraju 12 months ago

  • Target version set to Sprint 1 (29th April - 3rd May)
Actions #5

Updated by Sivakanth Kesiraju 12 months ago

  • Target version changed from Sprint 1 (29th April - 3rd May) to Security Audit
Actions #6

Updated by Gautam Kumar 7 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF