🎯 New Report #3114132: Broken Access Control Exposes Email Verification Status and Privacy Settings via API Endpoint
🔺Severity: Low
👽 Reporter: ctrl cipher
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-26
⏰ Disclosed: 2025-04-29 12:45:03
📝 Summary: The /api/v1/users/{username} endpoint leaked sensitive email-related metadata, such as the user's email confirmation status and privacy settings, without proper authorization checks. This allowed attackers to determine whether an account's email address was confirmed and the user's email privacy preferences, even if the email itself was hidden.
@hackeronereports
🔺Severity: Low
👽 Reporter: ctrl cipher
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-26
⏰ Disclosed: 2025-04-29 12:45:03
📝 Summary: The /api/v1/users/{username} endpoint leaked sensitive email-related metadata, such as the user's email confirmation status and privacy settings, without proper authorization checks. This allowed attackers to determine whether an account's email address was confirmed and the user's email privacy preferences, even if the email itself was hidden.
@hackeronereports
🎯 New Report #3051155: Information disclosure on IBM training service endpoint
🔺Severity: null
👽 Reporter: thpless
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-04-29 14:57:05
📝 Summary: The IBM training service endpoint had an information disclosure vulnerability that was reported to IBM, analyzed, and remediated. The vulnerability was discovered and reported by an external researcher.
@hackeronereports
🔺Severity: null
👽 Reporter: thpless
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-04-29 14:57:05
📝 Summary: The IBM training service endpoint had an information disclosure vulnerability that was reported to IBM, analyzed, and remediated. The vulnerability was discovered and reported by an external researcher.
@hackeronereports
🎯 New Report #3117697: Double Free Vulnerability in `libcurl` Cookie Management (`cookie.c`)
🔺Severity: null
👽 Reporter: tannicarcher
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-29
⏰ Disclosed: 2025-04-29 21:16:18
📝 Summary: null
@hackeronereports
🔺Severity: null
👽 Reporter: tannicarcher
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-29
⏰ Disclosed: 2025-04-29 21:16:18
📝 Summary: null
@hackeronereports
🎯 New Report #3116935: Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl
🔺Severity: null
👽 Reporter: tannicarcher
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-29
⏰ Disclosed: 2025-04-29 21:16:05
📝 Summary: null
@hackeronereports
🔺Severity: null
👽 Reporter: tannicarcher
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-29
⏰ Disclosed: 2025-04-29 21:16:05
📝 Summary: null
@hackeronereports
🎯 New Report #3114554: Privilege Persistence via Cloned Agent
🔺Severity: Medium
👽 Reporter: yoyomiski
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-27
⏰ Disclosed: 2025-04-30 07:07:43
📝 Summary: The vulnerability allowed a member to clone an agent managed by the admin by modifying the agent's unique identifier (sid). This resulted in the admin being unable to effectively disable the agent, as the cloned version could still be used by the member even after the original agent was disabled.
@hackeronereports
🔺Severity: Medium
👽 Reporter: yoyomiski
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-27
⏰ Disclosed: 2025-04-30 07:07:43
📝 Summary: The vulnerability allowed a member to clone an agent managed by the admin by modifying the agent's unique identifier (sid). This resulted in the admin being unable to effectively disable the agent, as the cloned version could still be used by the member even after the original agent was disabled.
@hackeronereports
🎯 New Report #3120790: Session Replay Attack Allows Authentication Bypass via Captured Login Responses Allowing Bypass of 429 Too many attempts for Multiple Failed Logins
🔺Severity: High
👽 Reporter: ctrl cipher
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-05-01
⏰ Disclosed: 2025-05-01 19:33:10
📝 Summary: null
@hackeronereports
🔺Severity: High
👽 Reporter: ctrl cipher
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-05-01
⏰ Disclosed: 2025-05-01 19:33:10
📝 Summary: null
@hackeronereports
🎯 New Report #3115705: Stored XSS in File Upload Leads to Privilege Escalation and Full Workspace Takeover
🔺Severity: High
👽 Reporter: sjalu
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-28
⏰ Disclosed: 2025-05-02 12:01:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the Dust platform's file upload functionality. An attacker could upload a malicious HTML file to a conversation. When another user, including an admin, visited the uploaded file, JavaScript was executed in their authenticated browser session. This allowed the attacker to issue authenticated API requests on behalf of the victim, including promoting their own account to admin, downgrading or removing legitimate admins, accessing and deleting secrets, and gaining full control over the workspace.
@hackeronereports
🔺Severity: High
👽 Reporter: sjalu
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-28
⏰ Disclosed: 2025-05-02 12:01:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the Dust platform's file upload functionality. An attacker could upload a malicious HTML file to a conversation. When another user, including an admin, visited the uploaded file, JavaScript was executed in their authenticated browser session. This allowed the attacker to issue authenticated API requests on behalf of the victim, including promoting their own account to admin, downgrading or removing legitimate admins, accessing and deleting secrets, and gaining full control over the workspace.
@hackeronereports
🎯 New Report #3088290: Middleware Authentication Bypass on IBM Portal
🔺Severity: Critical
👽 Reporter: muhammadwaseem3
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-04-11
⏰ Disclosed: 2025-05-02 14:58:27
📝 Summary: The vulnerability of middleware authentication bypass on the IBM Portal endpoint was reported, analyzed, and remediated. The discovery was reported by an external researcher.
@hackeronereports
🔺Severity: Critical
👽 Reporter: muhammadwaseem3
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-04-11
⏰ Disclosed: 2025-05-02 14:58:27
📝 Summary: The vulnerability of middleware authentication bypass on the IBM Portal endpoint was reported, analyzed, and remediated. The discovery was reported by an external researcher.
@hackeronereports
🎯 New Report #2265413: Open Redirect on https://api.fastly.com/
🔺Severity: Low
👽 Reporter: hasn0x
💼 Team: Fastly VDP
💵 Bounty: null
🕐 Submitted: 2023-11-27
⏰ Disclosed: 2025-05-02 19:10:10
📝 Summary: The open redirect vulnerability on https://api.fastly.com/ was discovered. The vulnerability allowed user redirection to a malicious website by modifying the "redirect url" parameter. The issue was identified through the steps provided in the report.
@hackeronereports
🔺Severity: Low
👽 Reporter: hasn0x
💼 Team: Fastly VDP
💵 Bounty: null
🕐 Submitted: 2023-11-27
⏰ Disclosed: 2025-05-02 19:10:10
📝 Summary: The open redirect vulnerability on https://api.fastly.com/ was discovered. The vulnerability allowed user redirection to a malicious website by modifying the "redirect url" parameter. The issue was identified through the steps provided in the report.
@hackeronereports
🎯 New Report #3097900: `/names.nsf` and all `/names*` files route to public API on rubygems.org
🔺Severity: None
👽 Reporter: jagat-singh
💼 Team: RubyGems
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-05-03 16:00:09
📝 Summary: null
@hackeronereports
🔺Severity: None
👽 Reporter: jagat-singh
💼 Team: RubyGems
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-05-03 16:00:09
📝 Summary: null
@hackeronereports
🎯 New Report #3125832: HTTP/3 Stream Dependency Cycle Exploit
🔺Severity: High
👽 Reporter: evilginx
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-04
⏰ Disclosed: 2025-05-04 15:52:29
📝 Summary: null
@hackeronereports
🔺Severity: High
👽 Reporter: evilginx
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-04
⏰ Disclosed: 2025-05-04 15:52:29
📝 Summary: null
@hackeronereports
🎯 New Report #3112106: BAC – Bypass chatbot restrictions via unauthorized mention injection
🔺Severity: Medium
👽 Reporter: yoyomiski
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-25
⏰ Disclosed: 2025-05-06 14:24:05
📝 Summary: The Gemini chatbot was found to have a vulnerability that allowed unauthorized users to bypass permission restrictions and interact with the chatbot. The vulnerability was discovered when a user manually edited the request by changing the "mention" and "configurationId" fields, which allowed them to communicate with the disabled Gemini chatbot despite not having the proper permissions.
@hackeronereports
🔺Severity: Medium
👽 Reporter: yoyomiski
💼 Team: Dust
💵 Bounty: null
🕐 Submitted: 2025-04-25
⏰ Disclosed: 2025-05-06 14:24:05
📝 Summary: The Gemini chatbot was found to have a vulnerability that allowed unauthorized users to bypass permission restrictions and interact with the chatbot. The vulnerability was discovered when a user manually edited the request by changing the "mention" and "configurationId" fields, which allowed them to communicate with the disabled Gemini chatbot despite not having the proper permissions.
@hackeronereports
🎯 New Report #3079966: HTML Injection in LinkedIn Premium Support Chat
🔺Severity: Low
👽 Reporter: nagu123
💼 Team: LinkedIn
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-05-07 07:53:59
📝 Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
@hackeronereports
🔺Severity: Low
👽 Reporter: nagu123
💼 Team: LinkedIn
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-05-07 07:53:59
📝 Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
<a> tags, was rendered in the chat and appeared clickable to support agents. The expected behavior was that user input in chat should have been sanitized and rendered as plain text without interpreting any HTML or tags.@hackeronereports
🎯 New Report #3060373: Path Traversal Vulnerability found on IBM Cloud
🔺Severity: Critical
👽 Reporter: 0x4bdo
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-03-26
⏰ Disclosed: 2025-05-07 17:43:20
📝 Summary: The path traversal vulnerability on IBM Cloud was reported by an external researcher, analyzed, and remediated. The vulnerability has been addressed.
@hackeronereports
🔺Severity: Critical
👽 Reporter: 0x4bdo
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-03-26
⏰ Disclosed: 2025-05-07 17:43:20
📝 Summary: The path traversal vulnerability on IBM Cloud was reported by an external researcher, analyzed, and remediated. The vulnerability has been addressed.
@hackeronereports
🎯 New Report #3080597: Unauthorized Account Access via Leaked Credentials in URL Format (Account Takeover )
🔺Severity: Critical
👽 Reporter: firec4t
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-05-07 23:08:32
📝 Summary: The vulnerability allowed attackers to access user accounts on khanAcademy.com using leaked credentials that were publicly available. The credentials were found in clear text format on a third-party website. By entering the email and password, the attacker could perform an account takeover without the user's knowledge or any secondary verification.
@hackeronereports
🔺Severity: Critical
👽 Reporter: firec4t
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-05-07 23:08:32
📝 Summary: The vulnerability allowed attackers to access user accounts on khanAcademy.com using leaked credentials that were publicly available. The credentials were found in clear text format on a third-party website. By entering the email and password, the attacker could perform an account takeover without the user's knowledge or any secondary verification.
@hackeronereports
🎯 New Report #3133379: CRLF Injection in `--proxy-header` allows extra HTTP headers (CWE-93)
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
⏰ Disclosed: 2025-05-08 08:21:52
📝 Summary: null
@hackeronereports
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
⏰ Disclosed: 2025-05-08 08:21:52
📝 Summary: null
@hackeronereports
🎯 New Report #2965723: Ability to access policy and updates for unauthorized program
🔺Severity: Medium
👽 Reporter: light3r
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-01-30
⏰ Disclosed: 2025-05-08 16:11:35
📝 Summary: The vulnerability allowed an unauthorized user with low permissions to access the policy and updates of a restricted program using an API key. The user was able to retrieve sensitive information, such as program policy and updates, despite not having the required access permissions.
@hackeronereports
🔺Severity: Medium
👽 Reporter: light3r
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-01-30
⏰ Disclosed: 2025-05-08 16:11:35
📝 Summary: The vulnerability allowed an unauthorized user with low permissions to access the policy and updates of a restricted program using an API key. The user was able to retrieve sensitive information, such as program policy and updates, despite not having the required access permissions.
@hackeronereports
🎯 New Report #3016540: Enable 2FA without verifying the email
🔺Severity: Low
👽 Reporter: samtime
💼 Team: XVIDEOS
💵 Bounty: null
🕐 Submitted: 2025-02-27
⏰ Disclosed: 2025-05-09 06:37:34
📝 Summary: null
@hackeronereports
🔺Severity: Low
👽 Reporter: samtime
💼 Team: XVIDEOS
💵 Bounty: null
🕐 Submitted: 2025-02-27
⏰ Disclosed: 2025-05-09 06:37:34
📝 Summary: null
@hackeronereports
🎯 New Report #2616045: Race condition on add 1 free domain
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2024-07-22
⏰ Disclosed: 2025-05-09 18:59:17
📝 Summary: A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain.
@hackeronereports
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2024-07-22
⏰ Disclosed: 2025-05-09 18:59:17
📝 Summary: A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain.
@hackeronereports
🎯 New Report #3137657: Memory Leak
🔺Severity: null
👽 Reporter: antypanty
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-09
⏰ Disclosed: 2025-05-10 21:16:26
📝 Summary: null
@hackeronereports
🔺Severity: null
👽 Reporter: antypanty
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-09
⏰ Disclosed: 2025-05-10 21:16:26
📝 Summary: null
@hackeronereports
🎯 New Report #2828693: change part of personal information all users
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:13:38
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:13:38
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports