Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by monty099 - 08.08.2026
Last edited by cbay - 08.08.2026

FS#435 - Title: Public Exposure of Sensitive Bank Details via PDF

Description

A publicly accessible PDF file exposes sensitive financial and personal information, including the account holder’s IBAN, BIC, name, and address.

Affected URLs:

* `https://static.alwaysdata.com/docs/IBAN.pdf`
* `https://share.alwaysdata.com/IBAN.pdf`

Steps to Reproduce

1. Visit either affected URL.
2. Download/open `IBAN.pdf`.
3. Observe the exposed banking and personal information.

Impact

* Exposure of sensitive financial information.
* Privacy violation and potential GDPR concerns.
* Increased risk of phishing, fraud, and targeted attacks.

Severity

High

Remediation

* Remove the PDF from public access immediately.
* Audit publicly accessible files for similar exposures.
* Ensure sensitive documents are stored behind proper access controls.
* Avoid relying solely on `robots.txt` or `noindex`, as these do not prevent direct access.

Conclusion

The PDF is accessible without authentication and exposes sensitive financial and personal information. The file should be removed or access-restricted as soon as possible. Any public disclosure of this report should have all sensitive information properly redacted.

Closed by  cbay
08.08.2026 08:31
Reason for closing:  Duplicate
Additional comments about closing:  

https://security.alwaysda ta.com/task/126

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing