Excessive Data Exposure

circle-info

Excessive Data Exposure occurs when an application unintentionally reveals more data than necessary, often through APIs or error messages.

triangle-exclamation
circle-check

The below example is based on the crAPIarrow-up-right application.

Figure 1: Identifying an excessive data exposure vulnerability.

The below example is based on HTB's API Attacksarrow-up-right module.

Figure 2: Discovering an Excessive Data Exposure flaw.

Last updated

Was this helpful?