Found a vulnerability in our competitors checkout

Making it clear, we have not and will not use this information for ill intent.

Recently I found a huge security vulnerability in our competitors 10-year old website that allows anyone on the web to view the receipts (after payment) including customer information, prices, names, addresses, last 4 digit of card number, and the suppliers information.

My question is, without our competitor doing a reverse uno-card and potentially flagging us as a bad actor in knowing this information, how would you approach this situation?

Mind you this competitor was first to market, has a MICH higher DR/DA and would do 20x our sales, on the same services and product.

Without sounding bad, how can we approach them and get a positive outcome for both of us? Ie. improve our business relationship/partnership rather then taking advantage of the above.

submitted by /u/Ok-Specialist9739
[link] [comments]

from hacking: security in practice https://ift.tt/302L5fU

Comments