Individual Bestbuy email subscription pages are apparently indexed by Google
10 hours ago
I stumbled upon this today because I googled a certain phrase and the first two results lead me to a personalized email (un)subscribe form with individual e-mail addresses at the top.
I thought that that was not great, so I submitted it to hackerone as per BB's responsible dislosure policy, but they closed the report and changed the status to "Informative".
> Thank you for your submission! Although your finding might appear to be a security vulnerability, this behavior does not really pose a concrete and exploitable risk to the platform. Bestbuy only view this as an issue if the links are obtainable from Bestbuy systems directly which doesn't appear to be the case here. Your effort is nonetheless appreciated and we wish that you'll continue to research and submit any future security issues you find.
Are they right, is this no big deal and am I overreacting?
Not sure if I should share the actual search term here that produces these URLs here, but I'd be happy to share it with dang.
No comments yet
Contribute on Hacker News ↗