- Status Closed
-
Assigned To
cbay - Private
Opened by SiddharthSharma - 28.07.2026
Last edited by cbay - 10.08.2026
FS#423 - Broken Object Level Authorization (IDOR) → Mass PII Disclosure
Severity: Critical
CVSS 3.1: 9.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Affected endpoint: https://admin.alwaysdata.com/domain/add/3/?_field_contact_domain=<ID>
Summary
The domain purchase wizard on admin.alwaysdata.com allows any authenticated free-tier user to retrieve the full registrant identity dossier of any other customer's domain by manipulating the _field_contact_domain GET parameter. The server fetches the victim's registrant record directly from the domain registrar and renders it in the browser.
I tested this against 100 different domain IDs across the platform and every single one returned a different customer's personal data. The vulnerability affects all domains on the platform, exposing the registrant PII of every customer who registered a domain through alwaysdata.
Leaked information:
Phone number, Registrant email address, Firstname, Lastname, Company name, Full Address, Postal code, Fax number, Tax identification number and etc.
Steps to Reproduce
1. Log in to https://admin.alwaysdata.com with any free account
2. Go to https://admin.alwaysdata.com/domain/add/1/ 3. Enter any domain name (e.g. testdomain123.fr), click Next step
4. Check the domain, select Create/register from the dropdown, click Next step
5. You are now on Step 3. Replace the URL with:
https://admin.alwaysdata.com/domain/add/3/?_field_contact_domain=251 6. The form pre-fills with another customer's full registrant identity — name, address, phone, email, SIREN, VAT
7. Change 251 to any other IDs to see different victims.
Each ID returns a different person's complete identity. I verified 100 — all returned PII and it leak all customers data.
Impact:
Any free-tier user can enumerate all domains on the platform and retrieve the full registrant identity of every domain owner — including first name, last name, postal address, phone number, email, company registration number (SIREN) and EU VAT number. I tested 100 domain IDs and every one returned a different real person's complete identity dossier. Critically, even customers who explicitly enabled alwaysdata's WHOIS privacy option ("Hide my details") are exposed. This constitutes a mass disclosure of EU citizens' personal data including national business identifiers, affecting every customer who registered a domain through alwaysdata.
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Alwaysdata Idor domain regist...
Hello, any update on this report?
Hello Team, any update?
Hello,
Can you confirm that the issue is fixed?
Kind regards,
Cyril
Hello, I have checked, The bug is FIXED now, and should i raise ticket on admin panel for reward?
Yes, please.