Difference between GDPR PII Exposure and Improper Access Control

Questions or suggestions about the platform
Post Reply
alexro2404
Posts:3
Joined:Fri Mar 02, 2018 5:19 pm
Difference between GDPR PII Exposure and Improper Access Control

Post by alexro2404 » Wed Apr 10, 2019 4:03 pm

Regards
I have a question with 2 vulnerabilities, in specific:
GDPR PII Exposure.- In the example that you put, an image with personal data such as email, telephone, date of birth is shown.
Improper Access Control.- A non-authenticated or authenticated user without privileges can access confidential data or administrative functions.

How would you know in which case GRDP PII applies and in which cases IAC applies, just to understand the difference well when trying to report those vulnerabilities, I hope you have given me to understand and can help me.

Thank you in advance and I look forward to your comments

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Difference between GDPR PII Exposure and Improper Access Control

Post by x1admin » Thu Apr 11, 2019 5:26 am

alexro2404 wrote:
Wed Apr 10, 2019 4:03 pm
Regards
I have a question with 2 vulnerabilities, in specific:
GDPR PII Exposure.- In the example that you put, an image with personal data such as email, telephone, date of birth is shown.
Improper Access Control.- A non-authenticated or authenticated user without privileges can access confidential data or administrative functions.

How would you know in which case GRDP PII applies and in which cases IAC applies, just to understand the difference well when trying to report those vulnerabilities, I hope you have given me to understand and can help me.

Thank you in advance and I look forward to your comments
Hello, difference in personal data

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests