An advisor, through the GLIA application, should not have access to client information. However, the advisor can obtain different client data (without the client being aware of it), simply by logging into the user window and following the flow that the user goes through when opening an account.
Obtain confidential information from users without their approval.
User information should not be exposed to a third party in any part of the account opening flow.
Attacker from the Internet with access to GLIA application.
Expected Remediation Time
⌚ 120 minutes.
Default score using CVSS 3.1. It may change depending on the context of the vulnerability.
- Attack vector: N
- Attack complexity: L
- Privileges required: L
- User interaction: R
- Scope: U
- Confidentiality: L
- Integrity: N
- Availability: N
- Exploit code madurity: X
- Remediation level: X
- Report confidence: X
- Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
- Base: 3.5
- Temporal: 3.5
- Base: Low
- Temporal: Low
User sensitive information is only accesible to an identifiable authorized user
Non compliant code
The application shows user sensitive information in the registration process without using some form of secure id validation
Search for vulnerabilities in your apps for free with our automated security testing! Start your 21-day free trial and discover the benefits of our Continuous Hacking Machine Plan. If you prefer a full service that includes the expertise of our ethical hackers, don't hesitate to contact us for our Continuous Hacking Squad Plan.