🎯 New Report #3079966: HTML Injection in LinkedIn Premium Support Chat
🔺Severity: Low
👽 Reporter: nagu123
💼 Team: LinkedIn
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-05-07 07:53:59
📝 Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
@hackeronereports
🔺Severity: Low
👽 Reporter: nagu123
💼 Team: LinkedIn
💵 Bounty: null
🕐 Submitted: 2025-04-06
⏰ Disclosed: 2025-05-07 07:53:59
📝 Summary: The vulnerability exists in the LinkedIn Premium support chat interface where unsanitized HTML input was rendered directly in the chat window. An attacker could have exploited this by injecting malicious HTML such as clickable links, potentially leading to phishing or redirection attacks on LinkedIn support staff. The observed behavior was that HTML, such as
<a> tags, was rendered in the chat and appeared clickable to support agents. The expected behavior was that user input in chat should have been sanitized and rendered as plain text without interpreting any HTML or tags.@hackeronereports
🎯 New Report #3060373: Path Traversal Vulnerability found on IBM Cloud
🔺Severity: Critical
👽 Reporter: 0x4bdo
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-03-26
⏰ Disclosed: 2025-05-07 17:43:20
📝 Summary: The path traversal vulnerability on IBM Cloud was reported by an external researcher, analyzed, and remediated. The vulnerability has been addressed.
@hackeronereports
🔺Severity: Critical
👽 Reporter: 0x4bdo
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-03-26
⏰ Disclosed: 2025-05-07 17:43:20
📝 Summary: The path traversal vulnerability on IBM Cloud was reported by an external researcher, analyzed, and remediated. The vulnerability has been addressed.
@hackeronereports
🎯 New Report #3080597: Unauthorized Account Access via Leaked Credentials in URL Format (Account Takeover )
🔺Severity: Critical
👽 Reporter: firec4t
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-05-07 23:08:32
📝 Summary: The vulnerability allowed attackers to access user accounts on khanAcademy.com using leaked credentials that were publicly available. The credentials were found in clear text format on a third-party website. By entering the email and password, the attacker could perform an account takeover without the user's knowledge or any secondary verification.
@hackeronereports
🔺Severity: Critical
👽 Reporter: firec4t
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-05-07 23:08:32
📝 Summary: The vulnerability allowed attackers to access user accounts on khanAcademy.com using leaked credentials that were publicly available. The credentials were found in clear text format on a third-party website. By entering the email and password, the attacker could perform an account takeover without the user's knowledge or any secondary verification.
@hackeronereports
🎯 New Report #3133379: CRLF Injection in `--proxy-header` allows extra HTTP headers (CWE-93)
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
⏰ Disclosed: 2025-05-08 08:21:52
📝 Summary: null
@hackeronereports
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
⏰ Disclosed: 2025-05-08 08:21:52
📝 Summary: null
@hackeronereports
🎯 New Report #2965723: Ability to access policy and updates for unauthorized program
🔺Severity: Medium
👽 Reporter: light3r
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-01-30
⏰ Disclosed: 2025-05-08 16:11:35
📝 Summary: The vulnerability allowed an unauthorized user with low permissions to access the policy and updates of a restricted program using an API key. The user was able to retrieve sensitive information, such as program policy and updates, despite not having the required access permissions.
@hackeronereports
🔺Severity: Medium
👽 Reporter: light3r
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-01-30
⏰ Disclosed: 2025-05-08 16:11:35
📝 Summary: The vulnerability allowed an unauthorized user with low permissions to access the policy and updates of a restricted program using an API key. The user was able to retrieve sensitive information, such as program policy and updates, despite not having the required access permissions.
@hackeronereports
🎯 New Report #3016540: Enable 2FA without verifying the email
🔺Severity: Low
👽 Reporter: samtime
💼 Team: XVIDEOS
💵 Bounty: null
🕐 Submitted: 2025-02-27
⏰ Disclosed: 2025-05-09 06:37:34
📝 Summary: null
@hackeronereports
🔺Severity: Low
👽 Reporter: samtime
💼 Team: XVIDEOS
💵 Bounty: null
🕐 Submitted: 2025-02-27
⏰ Disclosed: 2025-05-09 06:37:34
📝 Summary: null
@hackeronereports
🎯 New Report #2616045: Race condition on add 1 free domain
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2024-07-22
⏰ Disclosed: 2025-05-09 18:59:17
📝 Summary: A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain.
@hackeronereports
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2024-07-22
⏰ Disclosed: 2025-05-09 18:59:17
📝 Summary: A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain.
@hackeronereports
🎯 New Report #3137657: Memory Leak
🔺Severity: null
👽 Reporter: antypanty
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-09
⏰ Disclosed: 2025-05-10 21:16:26
📝 Summary: null
@hackeronereports
🔺Severity: null
👽 Reporter: antypanty
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-09
⏰ Disclosed: 2025-05-10 21:16:26
📝 Summary: null
@hackeronereports
🎯 New Report #2828693: change part of personal information all users
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:13:38
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:13:38
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports
🎯 New Report #3090123: insecure deserilize object leads to RCE On Sitecore (CVE-██████████-27218)
🔺Severity: Critical
👽 Reporter: reinhardtthe
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-04-12
⏰ Disclosed: 2025-05-12 16:04:46
📝 Summary: This critical vulnerability involved an insecure deserialization issue in Sitecore implementation, which was assigned CVE-2025-27218. The vulnerability allowed remote code execution through unsanitized user input in the ThumbnailsAccessToken header. The vulnerability was remediated by removing public access to the affected site, which was then protected behind Cloudflare WAF.
@hackeronereports
🔺Severity: Critical
👽 Reporter: reinhardtthe
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-04-12
⏰ Disclosed: 2025-05-12 16:04:46
📝 Summary: This critical vulnerability involved an insecure deserialization issue in Sitecore implementation, which was assigned CVE-2025-27218. The vulnerability allowed remote code execution through unsanitized user input in the ThumbnailsAccessToken header. The vulnerability was remediated by removing public access to the affected site, which was then protected behind Cloudflare WAF.
@hackeronereports
🎯 New Report #2828608: Users Data Exposure via Insecure Endpoint
🔺Severity: Medium
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:52:22
📝 Summary: An insecure endpoint on the Mars Royal Canin website exposed sensitive customer information without proper authentication. Personal data, including full names, phone numbers, email addresses, physical addresses, and postal codes, was accessible through a simple API endpoint that could be accessed by anyone. The endpoint revealed customer data when provided with a numeric code parameter, and all user information could potentially have been accessed by brute-forcing this parameter.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
⏰ Disclosed: 2025-05-12 15:52:22
📝 Summary: An insecure endpoint on the Mars Royal Canin website exposed sensitive customer information without proper authentication. Personal data, including full names, phone numbers, email addresses, physical addresses, and postal codes, was accessible through a simple API endpoint that could be accessed by anyone. The endpoint revealed customer data when provided with a numeric code parameter, and all user information could potentially have been accessed by brute-forcing this parameter.
@hackeronereports
🎯 New Report #3063026: debug.log leaked [█████████](https://hackerone.com/reports/3063026)
🔺Severity: Low
👽 Reporter: imeng
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-05-12 15:45:47
📝 Summary: The report identified a security vulnerability in the visitor management system that exposed a debug log file containing personally identifiable information. The log file was publicly accessible without authentication, allowing unauthorized access to sensitive user data. The vulnerability was classified as an instance of insecure storage of sensitive information. The issue was subsequently resolved when the website was closed at the end of 2024.
@hackeronereports
🔺Severity: Low
👽 Reporter: imeng
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-03-27
⏰ Disclosed: 2025-05-12 15:45:47
📝 Summary: The report identified a security vulnerability in the visitor management system that exposed a debug log file containing personally identifiable information. The log file was publicly accessible without authentication, allowing unauthorized access to sensitive user data. The vulnerability was classified as an instance of insecure storage of sensitive information. The issue was subsequently resolved when the website was closed at the end of 2024.
@hackeronereports
🎯 New Report #2887506: massive PII leakage for ███████
🔺Severity: Medium
👽 Reporter: thpless
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-12-08
⏰ Disclosed: 2025-05-12 15:44:05
📝 Summary: The report identified a security vulnerability in the visitor management system (mwcvisitor.royalcanin.com.cn) that exposed a log file containing personally identifiable information (PII) of users. The log file was directly accessible through a public URL without any authentication, allowing unauthorized access to sensitive personal data. The vulnerability was confirmed and subsequently resolved by the Mars team, as the site was closed at the end of 2024 and the endpoint is no longer accessible.
@hackeronereports
🔺Severity: Medium
👽 Reporter: thpless
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-12-08
⏰ Disclosed: 2025-05-12 15:44:05
📝 Summary: The report identified a security vulnerability in the visitor management system (mwcvisitor.royalcanin.com.cn) that exposed a log file containing personally identifiable information (PII) of users. The log file was directly accessible through a public URL without any authentication, allowing unauthorized access to sensitive personal data. The vulnerability was confirmed and subsequently resolved by the Mars team, as the site was closed at the end of 2024 and the endpoint is no longer accessible.
@hackeronereports
🎯 New Report #2915647: Netlify Authentication Token Exposed in Public Mozilla CI Logs
🔺Severity: Critical
👽 Reporter: samirsec0x01
💼 Team: Mozilla
💵 Bounty: 1500
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-05-13 09:35:01
📝 Summary: A critical vulnerability was discovered involving the exposure of a Netlify authentication token within publicly accessible logs. The token provided full access to the "Mozilla IT Web SRE" Netlify account, bypassing all restrictions. The token's permissions encompassed roles such as Owner, Developer, Billing Admin, Reviewer, Publisher, and Content Editor, granting complete control over site management, deployments, billing, and content configurations.
@hackeronereports
🔺Severity: Critical
👽 Reporter: samirsec0x01
💼 Team: Mozilla
💵 Bounty: 1500
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-05-13 09:35:01
📝 Summary: A critical vulnerability was discovered involving the exposure of a Netlify authentication token within publicly accessible logs. The token provided full access to the "Mozilla IT Web SRE" Netlify account, bypassing all restrictions. The token's permissions encompassed roles such as Owner, Developer, Billing Admin, Reviewer, Publisher, and Content Editor, granting complete control over site management, deployments, billing, and content configurations.
@hackeronereports
🎯 New Report #3098717: user api key leaked
🔺Severity: None
👽 Reporter: atasec
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-17
⏰ Disclosed: 2025-05-13 14:02:20
📝 Summary: The user's API key was found exposed in an older URL while testing the WakaTime tool. The API key successfully authenticated requests to a restricted endpoint, indicating that it was valid and granted access to protected resources.
@hackeronereports
🔺Severity: None
👽 Reporter: atasec
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-04-17
⏰ Disclosed: 2025-05-13 14:02:20
📝 Summary: The user's API key was found exposed in an older URL while testing the WakaTime tool. The API key successfully authenticated requests to a restricted endpoint, indicating that it was valid and granted access to protected resources.
@hackeronereports
🎯 New Report #2817648: Improper error handling in async cryptographic operations crashes process
🔺Severity: High
👽 Reporter: tniessen
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2024-11-02
⏰ Disclosed: 2025-05-14 22:30:56
📝 Summary: The C method SignTraits::DeriveBits() incorrectly called ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process.
@hackeronereports
🔺Severity: High
👽 Reporter: tniessen
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2024-11-02
⏰ Disclosed: 2025-05-14 22:30:56
📝 Summary: The C method SignTraits::DeriveBits() incorrectly called ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process.
@hackeronereports
🎯 New Report #3062122: [Xenoblade Chronicles X: Definitive Edition Unrestricted RPCs allow DoS and writing arbitrary flags remotely](https://hackerone.com/reports/3062122)
🔺Severity: Critical
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-31
⏰ Disclosed: 2025-05-15 00:11:16
📝 Summary: The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).
@hackeronereports
🔺Severity: Critical
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-31
⏰ Disclosed: 2025-05-15 00:11:16
📝 Summary: The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).
@hackeronereports
🎯 New Report #3052880: [Xenoblade Chronicles X: Definitive Edition Improper validation of names allows injecting formatting tags and bypassing profanity filter](https://hackerone.com/reports/3052880)
🔺Severity: Medium
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-23
⏰ Disclosed: 2025-05-15 00:11:06
📝 Summary: The vulnerability in Xenoblade Chronicles X: Definitive Edition allowed improper validation of names, enabling the injection of formatting tags and bypassing the profanity filter.
@hackeronereports
🔺Severity: Medium
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-23
⏰ Disclosed: 2025-05-15 00:11:06
📝 Summary: The vulnerability in Xenoblade Chronicles X: Definitive Edition allowed improper validation of names, enabling the injection of formatting tags and bypassing the profanity filter.
@hackeronereports
🎯 New Report #3085889: Weak Rate Limiting Controls in the (LOGIN) page Expose System to Brute Force and DoS Attacks
🔺Severity: Critical
👽 Reporter: hajjaj-
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-05-15 11:11:04
📝 Summary: null
@hackeronereports
🔺Severity: Critical
👽 Reporter: hajjaj-
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-05-15 11:11:04
📝 Summary: null
@hackeronereports
🎯 New Report #3099816: Open Redirect Vulnerability in OAuth Flow Leading to Potential Phishing Attack
🔺Severity: Low
👽 Reporter: delsec
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-18
⏰ Disclosed: 2025-05-15 11:10:40
📝 Summary: null
@hackeronereports
🔺Severity: Low
👽 Reporter: delsec
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-18
⏰ Disclosed: 2025-05-15 11:10:40
📝 Summary: null
@hackeronereports
🎯 New Report #3056937: Bedrock Guardrails Evasion with Prompt Formatting
🔺Severity: None
👽 Reporter: nkirk-nrlabs
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-05-15 16:12:27
📝 Summary: null
@hackeronereports
🔺Severity: None
👽 Reporter: nkirk-nrlabs
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-05-15 16:12:27
📝 Summary: null
@hackeronereports