← back to suncloud

SEVERITY RATING: 4/10

An authenticated API located at "axcel.schoolmgmtsys.com/dashboard" (can be accessed with a student account) is exposing these types of data:

Attackers could use these information against the victim.

For fixing it:

I would remove unnecessary teacher data (remember me token, the firebase token, and the email) unless if the email is necessary.