Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- This reporting script includes functionality to read full reply email bodies via an internal hmail proxy, which materially expands its privileges from campaign analytics into mailbox-content access. That creates unnecessary exposure of sensitive message contents and increases the blast radius if the script is misused or invoked in an unexpected context.
