quality: all 6+ 8+
7
0

A critical authorization bypass vulnerability in Companies House's web filing system allowed unauthenticated access to any of five million company dashboards by leveraging improper session state handling during the multi-step filing process. The flaw exposed directors' home addresses, email addresses, full dates of birth, and enabled potential modification of company details and account filings.

taxpolicy.org.uk · iamflimflam1· 29 days ago · 13 min · vulnerability · details · hn 4