DemocracyLab / DemocracyLab/CivicTechExchange

Application Leaks Sensitive Details Unnecessarily via API Calls

Open
#1,027 1 comment 0 reactions 1 assignee Claimed by @chenched05 View on GitHub
Back End bug
Dominant language
JavaScript
Stars
105
Forks
71
PR merge metrics
No merged PRs in 30d

Description

Application leaks sensitive/personal details unnecessarily via API calls. Further investigation is needed to determine the extent and all the instances.

Example: In the API call: `https://www.democracylab.org/api/team`, fields like **application_text** are returned. This field publicly reveals the application form details for contributors of a project.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.