Improper Access Control in OpenConsultingGroup/Flutter-Music-App

Valid
Reported on May 23rd 2021

✍️ Description

Your Firebase instance used in this repo can be read or written by anyone.

🕵️‍♂️ Proof of Concept

Please visit https://funkmusic-4387d.firebaseio.com/00.json to confirm that anyone is able to read and write into your Firebase instance.

💥 Impact

Anyone is able to read/write into your Firebase instance.