Skip to content
fvewebauthenticationsensitive-data-exposureredacted

[Personal Data Exposure] Resident-Number-Based Linking Information Exposed by a Missing Authentication-Level Check

2 min read

Overview

In the password-recovery flow, the endpoint that checks whether identity verification is still valid did not check the authentication level, so it could be called even from an anonymous session. Its response contained the victim's resident-number-based linking information (CI), phone number, date of birth, gender and real name in plain text.

This is an abridged record. The product name, vendor name, paths, parameter names and reproduction steps are masked.

Disclosure details

  • ID: FVE-2026-8617-74513
  • Group: Web
  • Status: Published
  • Severity: High (CVSS 7.5, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
  • Submitted: 2026-05-20, issued: 2026-06-05
  • Visibility: Redacted

Attack flow

[Step 1] Obtain a member-number-based identifier
  - Requires the preceding object-level authorization flaw

[Step 2] Obtain an authenticated session
  - Whether login actually completed is not checked

[Step 3] Request the identity-verification validity check
  - Returns a success response even for an anonymous session
  - Exposes CI, phone number, date of birth, gender and real name

Impact

  • Exposure of resident-number-based linking information (CI)
  • Simultaneous exposure of real name, phone number, date of birth and gender
  • Can be abused for smishing, voice phishing and account-takeover attempts
  • Allows mass collection when combined with sequential member-number enumeration

Remediation

  1. Add an authentication-level check to the endpoint.
  2. Verify on the server that the session owns the queried record.
  3. Minimize sensitive identifiers such as CI in responses.
  4. Block the preceding object-level authorization flaw first.

Platform evaluation

  • Medium
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/SH:B/DO:A

CWE

No CWE is published for this masked record.