SpiceJet Online Booking System Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability in SpiceJet's online booking system allows unauthorized access to full passenger booking details using only a PNR and last name. This issue, stemming from improper access control on a sensitive data retrieval function, exposes extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess these basic inputs.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive personal and booking information.

Added: Apr 23, 2026, 9:29 PM
Updated: Apr 23, 2026, 9:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.4
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.