--

Most of the time you can see some informative info in this directory. But sometime you may get internal custom field names and custom SLA names via this endpoint. Then it is a bug and you can report it.

Exploit:

It is very easy. Just go to the endpoint to fetch this data.

--

--

Professor Software Solutions
Professor Software Solutions

Written by Professor Software Solutions

Bug Bounty Hunter at HackerOne Inc | Cybersecurity Enthusiast | Passionate About Finding Vulnerabilities and Enhancing Online Security | https://x.com/bughuntar

Responses (1)