Skip to content

Vulnerability Report- Sensitive Information Disclosure #13

@Phoenix202020

Description

@Phoenix202020

Weakness: Sensitive Information Disclosure

Severity: Medium-High- CWE-200

Target : https://github.com/FUSIONFoundation/myfusionwallet

Summary:

After some research, I found a leak that leads to accessing sensitive data of API key.Such keys are vulnerable and has been misused before by the attackers.

POC:

Sensitive Information Leakage:

https://github.com/FUSIONFoundation/myfusionwallet/blob/aaa11e329e9a81fb47b9a400aa7f32178f16bee0/app/scripts/nodeHelpers/etherscan.js#L113

Impact:

High potential of an unauthorized access to PII data and misuage/attack.

Looking forward to hear from you soon on this.

Regards,
Phoenix

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions