Ecatepec.gob.mx

DBHunter

DBHunter

Infinity Member
Golden Member
Joined
August 23, 2025
Messages
2,519
Reaction score
6,442
Points
113
  • Thread Author
  • #1
A misconfiguration on ecatepec.gob.mx exposes sensitive personal documents belonging to citizens, including valid government-issued identification (INE), CURP records, birth certificates, proof of address, résumés (CVs), and other personally identifiable information (PII). The exposed documents remain publicly accessible and can be downloaded without authentication or any access restrictions.

Additionally, a centralized CSV dataset containing sensitive information was accessible, including references to INE records, CURPs, birth certificates, proof of residence, and CVs, allowing an attacker to efficiently aggregate and process large amounts of personal data.

Furthermore, the application allows active user enumeration through publicly accessible sitemaps and distinguishable authentication error responses. This enables attackers to identify valid accounts, facilitating credential stuffing, brute-force attacks, account takeover attempts, and identity impersonation.

The combination of unrestricted access to sensitive identity documents and user enumeration substantially increases the overall risk, potentially enabling identity theft, social engineering, fraudulent account creation, and other malicious activities.​

To see this hidden content, you need to "Reply & React" with one of the following reactions: Like Like, Love Love, Haha Haha, Wow Wow
 
  • Tags
    breach-information cybersecurity-news data-leak-download ecatepec-download hacked-database