Critical sensitive information Disclosure. [HtUS]

Program: U.S. Dept Of Defense Bug Type: Information Disclosure Bounty: Unspecified Date: 2022-07-05
information-disclosure sensitive-data-leak

Summary

The researcher found an endpoint - /database.php.orig where database credentials were exposed in source in plaintext.

References