🎯 New Report #3176981: Stored Cross-Site Scripting (XSS) in "Add Contact" Name Field – MainWP Plugin
🔺Severity: null
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-04
⏰ Disclosed: 2025-07-17 09:07:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the MainWP WordPress plugin. The vulnerability was found in the "Add Contact" > Contact Name field, where user input was not properly sanitized before rendering it back into the DOM. As a result, an attacker could inject malicious JavaScript payloads that would be executed in the browser of any user, typically an administrator, who viewed the infected client profile.
📂 Report JSON File: 3176981
@hackeronereports
🔺Severity: null
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-04
⏰ Disclosed: 2025-07-17 09:07:14
📝 Summary: A stored cross-site scripting (XSS) vulnerability was discovered in the MainWP WordPress plugin. The vulnerability was found in the "Add Contact" > Contact Name field, where user input was not properly sanitized before rendering it back into the DOM. As a result, an attacker could inject malicious JavaScript payloads that would be executed in the browser of any user, typically an administrator, who viewed the infected client profile.
📂 Report JSON File: 3176981
@hackeronereports
🎯 New Report #3178999: Account takeover of existing HackerOne accounts through SCIM provisioning
🔺Severity: High
👽 Reporter: boy child
⭐️ Reputation: 727
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-06-05
⏰ Disclosed: 2025-07-17 14:12:57
📝 Summary: The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the victim account to the attacker's user, change the email parameter, and reset the password to gain access to the victim's account. The vulnerability existed due to issues with how the username and email fields were handled during the SCIM provisioning process.
📂 Report JSON File: 3178999
@hackeronereports
🔺Severity: High
👽 Reporter: boy child
⭐️ Reputation: 727
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2025-06-05
⏰ Disclosed: 2025-07-17 14:12:57
📝 Summary: The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the victim account to the attacker's user, change the email parameter, and reset the password to gain access to the victim's account. The vulnerability existed due to issues with how the username and email fields were handled during the SCIM provisioning process.
📂 Report JSON File: 3178999
@hackeronereports
🔥1
🎯 New Report #2831902: [CRITICAL 0-Click Account Takeover via Password Reset AUTH-3243 /orchestrator/v1/password reset/start](https://hackerone.com/reports/2831902)
🔺Severity: Critical
👽 Reporter: db3wy
⭐️ Reputation: 235
🛠 State: resolved
💼 Team: Remitly
💵 Bounty: null
🕐 Submitted: 2024-11-10
⏰ Disclosed: 2025-07-21 22:23:32
📝 Summary: The vulnerability discovered allowed an attacker to reset the password of a victim's account without any user interaction or special privileges. The attacker could intercept the password reset request, modify it with the victim's session data, and successfully take over the victim's account.
📂 Report JSON File: 2831902
@hackeronereports
🔺Severity: Critical
👽 Reporter: db3wy
⭐️ Reputation: 235
🛠 State: resolved
💼 Team: Remitly
💵 Bounty: null
🕐 Submitted: 2024-11-10
⏰ Disclosed: 2025-07-21 22:23:32
📝 Summary: The vulnerability discovered allowed an attacker to reset the password of a victim's account without any user interaction or special privileges. The attacker could intercept the password reset request, modify it with the victim's session data, and successfully take over the victim's account.
📂 Report JSON File: 2831902
@hackeronereports
🔥1
🎯 New Report #3205667: XSS on Amazon Aquisition: elemental
🔺Severity: High
👽 Reporter: muhammad kasim
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-06-17
⏰ Disclosed: 2025-07-22 00:48:09
📝 Summary: The XSS vulnerability on Amazon's acquisition of Elemental was identified and addressed. The summary provided a brief overview of the issue.
📂 Report JSON File: 3205667
@hackeronereports
🔺Severity: High
👽 Reporter: muhammad kasim
⭐️ Reputation: 92
🛠 State: resolved
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-06-17
⏰ Disclosed: 2025-07-22 00:48:09
📝 Summary: The XSS vulnerability on Amazon's acquisition of Elemental was identified and addressed. The summary provided a brief overview of the issue.
📂 Report JSON File: 3205667
@hackeronereports
🎯 New Report #3258022: curl ASSERTs when accessing an LDAP URL
🔺Severity: null
👽 Reporter: cmeister2
⭐️ Reputation: 159
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-17
⏰ Disclosed: 2025-07-22 08:02:49
📝 Summary: null
📂 Report JSON File: 3258022
@hackeronereports
🔺Severity: null
👽 Reporter: cmeister2
⭐️ Reputation: 159
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-17
⏰ Disclosed: 2025-07-22 08:02:49
📝 Summary: null
📂 Report JSON File: 3258022
@hackeronereports
🎯 New Report #1148364: Mint Oauth2 access token for targeted user
🔺Severity: High
👽 Reporter: timothyleung
⭐️ Reputation: 168
🛠 State: resolved
💼 Team: GitLab
💵 Bounty: null
🕐 Submitted: 2021-04-04
⏰ Disclosed: 2025-07-23 00:06:09
📝 Summary: The vulnerability allowed a group owner to create an application that was trusted by default, bypassing CSRF controls for the authorization flow. This enabled the minting of access tokens for targeted users without their consent.
📂 Report JSON File: 1148364
@hackeronereports
🔺Severity: High
👽 Reporter: timothyleung
⭐️ Reputation: 168
🛠 State: resolved
💼 Team: GitLab
💵 Bounty: null
🕐 Submitted: 2021-04-04
⏰ Disclosed: 2025-07-23 00:06:09
📝 Summary: The vulnerability allowed a group owner to create an application that was trusted by default, bypassing CSRF controls for the authorization flow. This enabled the minting of access tokens for targeted users without their consent.
📂 Report JSON File: 1148364
@hackeronereports
🎯 New Report #3255707: Windows Device Names Still Allow Path Traversal in UNC Paths After CVE-2025-27210 Fix
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 248
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-07-28 18:56:39
📝 Summary: null
📂 Report JSON File: 3255707
@hackeronereports
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 248
🛠 State: informative
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-07-28 18:56:39
📝 Summary: null
📂 Report JSON File: 3255707
@hackeronereports
🎯 New Report #3126603: RXSS on ██████ via customerId parameter
🔺Severity: Medium
👽 Reporter: 0xun7h1nk4ble
⭐️ Reputation: 309
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-05
⏰ Disclosed: 2025-07-28 19:17:42
📝 Summary: A Reflected Cross-Site Scripting (XSS) vulnerability was identified on the Mars website at ██████. The vulnerability was located in the customerId parameter, which was inadequately sanitized before being reflected back to users in the HTTP response. When the parameter was manipulated with malicious JavaScript code, the injected script was executed in the context of the user's browser.
📂 Report JSON File: 3126603
@hackeronereports
🔺Severity: Medium
👽 Reporter: 0xun7h1nk4ble
⭐️ Reputation: 309
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-05
⏰ Disclosed: 2025-07-28 19:17:42
📝 Summary: A Reflected Cross-Site Scripting (XSS) vulnerability was identified on the Mars website at ██████. The vulnerability was located in the customerId parameter, which was inadequately sanitized before being reflected back to users in the HTTP response. When the parameter was manipulated with malicious JavaScript code, the injected script was executed in the context of the user's browser.
📂 Report JSON File: 3126603
@hackeronereports
🎯 New Report #3261310: OpenSSL HTTP/3 bogus CURLINFO TLS SSL PTR
🔺Severity: null
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-20
⏰ Disclosed: 2025-07-28 22:48:50
📝 Summary: null
📂 Report JSON File: 3261310
@hackeronereports
🔺Severity: null
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-20
⏰ Disclosed: 2025-07-28 22:48:50
📝 Summary: null
📂 Report JSON File: 3261310
@hackeronereports
🎯 New Report #2995025: Mozilla VPN Clients: RCE via file write and path traversal
🔺Severity: High
👽 Reporter: trein
⭐️ Reputation: 1688
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-02-15
⏰ Disclosed: 2025-07-29 09:53:41
📝 Summary: The report describes a path traversal vulnerability in the Mozilla VPN client software that allowed for remote code execution. The vulnerability was found in the "live reload" command of the client's inspector feature, which could be accessed when the client was in developer mode with "Use Staging Servers" enabled. The vulnerable code in the InspectorHotreloader::fetchAndAnnounce() function failed to properly sanitize file paths when downloading remote files to a temporary folder, enabling attackers to write arbitrary files to any location on the filesystem.
📂 Report JSON File: 2995025
@hackeronereports
🔺Severity: High
👽 Reporter: trein
⭐️ Reputation: 1688
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-02-15
⏰ Disclosed: 2025-07-29 09:53:41
📝 Summary: The report describes a path traversal vulnerability in the Mozilla VPN client software that allowed for remote code execution. The vulnerability was found in the "live reload" command of the client's inspector feature, which could be accessed when the client was in developer mode with "Use Staging Servers" enabled. The vulnerable code in the InspectorHotreloader::fetchAndAnnounce() function failed to properly sanitize file paths when downloading remote files to a temporary folder, enabling attackers to write arbitrary files to any location on the filesystem.
📂 Report JSON File: 2995025
@hackeronereports
🔥1
🎯 New Report #3175695: Bypass "No Links" Restriction in Biography via Protocol-Relative URL (//)
🔺Severity: Low
👽 Reporter: yoyomiski
⭐️ Reputation: 210
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-07-29 14:43:32
📝 Summary: The report identifies a bypass vulnerability in the biography field on addons.allizom.org. Despite the application's policy against allowing links, it was possible to embed functional hyperlinks using protocol-relative URLs (//evil.com). This violation of the declared application policy was achieved by including an <a> tag with the protocol-relative URL.
📂 Report JSON File: 3175695
@hackeronereports
🔺Severity: Low
👽 Reporter: yoyomiski
⭐️ Reputation: 210
🛠 State: resolved
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-07-29 14:43:32
📝 Summary: The report identifies a bypass vulnerability in the biography field on addons.allizom.org. Despite the application's policy against allowing links, it was possible to embed functional hyperlinks using protocol-relative URLs (//evil.com). This violation of the declared application policy was achieved by including an <a> tag with the protocol-relative URL.
📂 Report JSON File: 3175695
@hackeronereports
😁1
🎯 New Report #2280279: total Failure of password protection while extracting seed phrase! increases attack surface area for scammers
🔺Severity: Medium
👽 Reporter: bug vs me
⭐️ Reputation: 2580
🛠 State: resolved
💼 Team: MetaMask
💵 Bounty: 3500
🕐 Submitted: 2023-12-10
⏰ Disclosed: 2025-07-31 19:36:43
📝 Summary: The MetaMask browser extension UI was able to access a user's seed phrase without requiring password confirmation, which violated expected security boundaries between the UI and background process. The issue was resolved in MetaMask Extension version 11.7.1, which now enforces password confirmation before any UI code can access the wallet's seed phrase.
📂 Report JSON File: 2280279
@hackeronereports
🔺Severity: Medium
👽 Reporter: bug vs me
⭐️ Reputation: 2580
🛠 State: resolved
💼 Team: MetaMask
💵 Bounty: 3500
🕐 Submitted: 2023-12-10
⏰ Disclosed: 2025-07-31 19:36:43
📝 Summary: The MetaMask browser extension UI was able to access a user's seed phrase without requiring password confirmation, which violated expected security boundaries between the UI and background process. The issue was resolved in MetaMask Extension version 11.7.1, which now enforces password confirmation before any UI code can access the wallet's seed phrase.
📂 Report JSON File: 2280279
@hackeronereports
🎯 New Report #3279508: Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards
🔺Severity: Medium
👽 Reporter: ctrl cipher
⭐️ Reputation: 201
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-07-31
⏰ Disclosed: 2025-08-03 03:23:03
📝 Summary: The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and members, even when the users had not chosen to make their emails public.
📂 Report JSON File: 3279508
@hackeronereports
🔺Severity: Medium
👽 Reporter: ctrl cipher
⭐️ Reputation: 201
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-07-31
⏰ Disclosed: 2025-08-03 03:23:03
📝 Summary: The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and members, even when the users had not chosen to make their emails public.
📂 Report JSON File: 3279508
@hackeronereports
🎯 New Report #3287060: Double Clickjacking Attack on WakaTime OAuth Authorization Flow at https://wakatime.com/oauth/authorize
🔺Severity: Medium
👽 Reporter: zeesozee
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-08-05
⏰ Disclosed: 2025-08-05 23:25:44
📝 Summary: The WakaTime OAuth authorization flow was vulnerable to a double-clickjacking attack. The attack allowed an attacker to trick users into unknowingly clicking the "Connect my WakaTime account" button in the consent dialog, enabling the attacker to register an OAuth application, capture the authorization code, and exchange it for an access token. This granted the attacker full access to defined permissions on behalf of the victim.
📂 Report JSON File: 3287060
@hackeronereports
🔺Severity: Medium
👽 Reporter: zeesozee
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: WakaTime
💵 Bounty: null
🕐 Submitted: 2025-08-05
⏰ Disclosed: 2025-08-05 23:25:44
📝 Summary: The WakaTime OAuth authorization flow was vulnerable to a double-clickjacking attack. The attack allowed an attacker to trick users into unknowingly clicking the "Connect my WakaTime account" button in the consent dialog, enabling the attacker to register an OAuth application, capture the authorization code, and exchange it for an access token. This granted the attacker full access to defined permissions on behalf of the victim.
📂 Report JSON File: 3287060
@hackeronereports
🎯 New Report #3290630: Sample report: Denial of service
🔺Severity: None
👽 Reporter: ghbountyocto
⭐️ Reputation: 121
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: null
🕐 Submitted: 2025-08-07
⏰ Disclosed: 2025-08-07 16:40:12
📝 Summary: The denial of service vulnerability was identified in the system. The vulnerability could have allowed an attacker to disrupt the availability of the system by exhausting its resources.
📂 Report JSON File: 3290630
@hackeronereports
🔺Severity: None
👽 Reporter: ghbountyocto
⭐️ Reputation: 121
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: null
🕐 Submitted: 2025-08-07
⏰ Disclosed: 2025-08-07 16:40:12
📝 Summary: The denial of service vulnerability was identified in the system. The vulnerability could have allowed an attacker to disrupt the availability of the system by exhausting its resources.
📂 Report JSON File: 3290630
@hackeronereports
🎯 New Report #3174987: Man-in-the-middle through broken SSL certificate verification
🔺Severity: Medium
👽 Reporter: kinnay
⭐️ Reputation: 724
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-08-08 01:22:09
📝 Summary: The vulnerability allowed an attacker to perform a man-in-the-middle attack by bypassing SSL certificate verification.
📂 Report JSON File: 3174987
@hackeronereports
🔺Severity: Medium
👽 Reporter: kinnay
⭐️ Reputation: 724
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-08-08 01:22:09
📝 Summary: The vulnerability allowed an attacker to perform a man-in-the-middle attack by bypassing SSL certificate verification.
📂 Report JSON File: 3174987
@hackeronereports
🎯 New Report #3221185: Exceed the maximum number of subscribers using Race Condition
🔺Severity: Low
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
⏰ Disclosed: 2025-08-12 19:52:29
📝 Summary: A race condition vulnerability was discovered in the SingleStore control panel that allowed bypassing the maximum limit of five subscribers for alerts. The issue was patched and deployed to production.
📂 Report JSON File: 3221185
@hackeronereports
🔺Severity: Low
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
⏰ Disclosed: 2025-08-12 19:52:29
📝 Summary: A race condition vulnerability was discovered in the SingleStore control panel that allowed bypassing the maximum limit of five subscribers for alerts. The issue was patched and deployed to production.
📂 Report JSON File: 3221185
@hackeronereports
🎯 New Report #3219944: IDOR - Scheduled data leak to other accounts By "projectID"
🔺Severity: Medium
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
⏰ Disclosed: 2025-08-12 19:47:48
📝 Summary: The Insecure Direct Object Reference (IDOR) vulnerability was discovered in the GetNotebookScheduledPaginatedJobs endpoint on backend.singlestore.com. The API failed to verify the requestor's permission to access the specified project, allowing an authenticated user to access scheduled job information belonging to other users' projects by modifying the projectID parameter. The vulnerability exposed sensitive information such as database names, notebook paths, scheduling details, and infrastructure information.
📂 Report JSON File: 3219944
@hackeronereports
🔺Severity: Medium
👽 Reporter: q11x
⭐️ Reputation: 411
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-06-25
⏰ Disclosed: 2025-08-12 19:47:48
📝 Summary: The Insecure Direct Object Reference (IDOR) vulnerability was discovered in the GetNotebookScheduledPaginatedJobs endpoint on backend.singlestore.com. The API failed to verify the requestor's permission to access the specified project, allowing an authenticated user to access scheduled job information belonging to other users' projects by modifying the projectID parameter. The vulnerability exposed sensitive information such as database names, notebook paths, scheduling details, and infrastructure information.
📂 Report JSON File: 3219944
@hackeronereports
🎯 New Report #3113398: Internal Access to Hackerone confluence Docs
🔺Severity: High
👽 Reporter: madara
⭐️ Reputation: 3339
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: $12,500
🕐 Submitted: 2025-04-26
⏰ Disclosed: 2025-08-13 22:05:42
📝 Summary: During testing on ticketing platforms, it was discovered that HackerOne's support ticket system was misconfigured, introducing a security risk. The email
📂 Report JSON File: 3113398
@hackeronereports
🔺Severity: High
👽 Reporter: madara
⭐️ Reputation: 3339
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: $12,500
🕐 Submitted: 2025-04-26
⏰ Disclosed: 2025-08-13 22:05:42
📝 Summary: During testing on ticketing platforms, it was discovered that HackerOne's support ticket system was misconfigured, introducing a security risk. The email
███████ was enabled to create and manage tickets on the support platform, allowing an attacker to abuse the ticketing system to register users on third-party platforms impersonating the domain @hackerone.com.📂 Report JSON File: 3113398
@hackeronereports
🔥1
🎯 New Report #3250315: █.8x8.vc/index.js: Exposed Google Maps API Key Allowing Potential Abuse of Paid Services
🔺Severity: Medium
👽 Reporter: abdallasamir12
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: 8x8 Bounty
💵 Bounty: 500
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-08-14 01:30:47
📝 Summary: The Google Maps API key was inadvertently exposed in client-side code, allowing potential unauthorized access to some Google Maps services. The issue was promptly addressed by implementing appropriate API key restrictions where feasible.
📂 Report JSON File: 3250315
@hackeronereports
🔺Severity: Medium
👽 Reporter: abdallasamir12
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: 8x8 Bounty
💵 Bounty: 500
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-08-14 01:30:47
📝 Summary: The Google Maps API key was inadvertently exposed in client-side code, allowing potential unauthorized access to some Google Maps services. The issue was promptly addressed by implementing appropriate API key restrictions where feasible.
📂 Report JSON File: 3250315
@hackeronereports
🎯 New Report #1848940: URL Path Manipulation Enables Cache Poisoning of Amazon Affiliate Products in Shopify Linkpop
🔺Severity: Low
👽 Reporter: saltymermaid
⭐️ Reputation: 1020
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: 500
🕐 Submitted: 2023-01-27
⏰ Disclosed: 2025-08-14 15:14:43
📝 Summary: The Shopify Linkpop service was found vulnerable to a cache poisoning issue that allowed attackers to manipulate the display of Amazon affiliate products. By crafting malicious URLs, attackers could trick victims into linking to the attacker's products instead of the intended ones. This vulnerability was not fixed, as the Linkpop service was scheduled for decommissioning.
📂 Report JSON File: 1848940
@hackeronereports
🔺Severity: Low
👽 Reporter: saltymermaid
⭐️ Reputation: 1020
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: 500
🕐 Submitted: 2023-01-27
⏰ Disclosed: 2025-08-14 15:14:43
📝 Summary: The Shopify Linkpop service was found vulnerable to a cache poisoning issue that allowed attackers to manipulate the display of Amazon affiliate products. By crafting malicious URLs, attackers could trick victims into linking to the attacker's products instead of the intended ones. This vulnerability was not fixed, as the Linkpop service was scheduled for decommissioning.
📂 Report JSON File: 1848940
@hackeronereports