html-comments

1 article
sort: new top best
clear filter
0 5/10

A bug bounty hunter discovered an information disclosure vulnerability in an enrollment portal where sensitive PII (last 4 SSN digits, account numbers, and verification answers) was exposed through missing rate limiting and HTML comments in the page source code, allowing account verification bypass.

Spazzy
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details