CoinEx Global Disclosed Report

Bug bounty report CoinEx Web & Mobile

Exposure of CodeIgniter .editorconfig File

Created date
May 31 2024

Target

https://www.coinex.com/en/

Vulnerability Details

A sensitive data disclosure vulnerability is a vulnerability through which unauthorised persons can gain access to confidential or proprietary information. Such vulnerabilities can result in the exposure of sensitive data such as personal information, financial data, medical records or trade secrets.

Validation steps

IP Address Discovery: Using Shodan, I found the real IP address of https://www.coinex.com/en/ under Cloudflare protection (205.234.144.41).

.editorconfig File Discovery: At this IP address, I scanned the web server for sensitive files and discovered that the .editorconfig file was accessible.

Attachments

Ekran_Resmi_2024-05-31_20.28.22.png
Ekran_Resmi_2024-05-31_19.14.10.png
CommentsReport History
Comments on this report are hidden
Details
Statedisclosed
Severity
Low
Bounty
hidden
Visibilitypartially
VulnerabilitySensitive Data Exposure
Participants (3)
triage team
author
company admin