Hackerone Reports
227 subscribers
744 links
Last Check 2026-09-20 13:45:01
Download Telegram
🎯 New Report #3371414: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable Cloud)
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: d0maxploit
⭐️ Reputation: 114
πŸ›  State: resolved
πŸ’Ό Team: Lovable VDP
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 20:32:59
πŸ“ Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
πŸ“‚ Report JSON File: 3371414
@hackeronereports
🎯 New Report #3371448: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable AI)
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: d0maxploit
⭐️ Reputation: 114
πŸ›  State: resolved
πŸ’Ό Team: Lovable VDP
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-05
⏰ Disclosed: 2025-11-04 22:54:23
πŸ“ Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
πŸ“‚ Report JSON File: 3371448
@hackeronereports
🎯 New Report #3355218: CVE-2025-10966: missing SFTP host verification with wolfSSH
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: giant anteater
⭐️ Reputation: 123
πŸ›  State: resolved
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-09-23
⏰ Disclosed: 2025-11-05 21:57:54
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3355218
@hackeronereports
🎯 New Report #3335709: SQL Injection in Django ORM via Unvalidated ` connector` in Q Objects
πŸ”ΊSeverity: Critical
πŸ‘½ Reporter: cyberstan
⭐️ Reputation: 92
πŸ›  State: resolved
πŸ’Ό Team: Django
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-09-12
⏰ Disclosed: 2025-11-06 21:09:42
πŸ“ Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
πŸ“‚ Report JSON File: 3335709
@hackeronereports
🎯 New Report #3369843: Low-privileged user can enable or disable Lovable AI for new projects in workspace
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: anxioussick
⭐️ Reputation: 129
πŸ›  State: resolved
πŸ’Ό Team: Lovable VDP
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-03
⏰ Disclosed: 2025-11-07 03:52:10
πŸ“ Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
πŸ“‚ Report JSON File: 3369843
@hackeronereports
🎯 New Report #3378635: Unauthorized Password Reset Allows Account Takeover Across Tenant Boundaries
πŸ”ΊSeverity: High
πŸ‘½ Reporter: mcdave
⭐️ Reputation: 107
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
πŸ“ Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
πŸ“‚ Report JSON File: 3378635
@hackeronereports
🎯 New Report #3414088: SMTP CRLF Command Injection in CURLOPT MAIL FROM and CURLOPT MAIL RCPT
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: bau1u
⭐️ Reputation: 116
πŸ›  State: duplicate
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3414088
@hackeronereports
🎯 New Report #3417428: libcurl MQTT `CURLOPT POSTFIELDSIZE LARGE` overflow leads to immediate DoS
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: jiyong
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3417428
@hackeronereports
🎯 New Report #3079738: Two click Account Takeover
πŸ”ΊSeverity: High
πŸ‘½ Reporter: fr4via
⭐️ Reputation: 11240
πŸ›  State: resolved
πŸ’Ό Team: Basecamp
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
πŸ“ Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
πŸ“‚ Report JSON File: 3079738
@hackeronereports
🎯 New Report #3419636: Authentication Token Theft via Open Redirect in Callback URL Parameter
πŸ”ΊSeverity: Critical
πŸ‘½ Reporter: sle3pyhead
⭐️ Reputation: 96
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-11
⏰ Disclosed: 2025-11-14 15:26:16
πŸ“ Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
πŸ“‚ Report JSON File: 3419636
@hackeronereports
🎯 New Report #3382796: Responsible disclosure - public S3 bucket exposing JSON/config files
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: xtawb
⭐️ Reputation: 29
πŸ›  State: resolved
πŸ’Ό Team: AWS VDP
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-14
⏰ Disclosed: 2025-11-14 19:25:28
πŸ“ Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
πŸ“‚ Report JSON File: 3382796
@hackeronereports
🎯 New Report #3427670: Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash
πŸ”ΊSeverity: null
πŸ‘½ Reporter: xkernel
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-16
⏰ Disclosed: 2025-11-16 22:40:20
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3427670
@hackeronereports
🎯 New Report #3417162: Authentication Bypass in Subscription Management Endpoint
πŸ”ΊSeverity: Critical
πŸ‘½ Reporter: 0hmz
⭐️ Reputation: 135
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-09
⏰ Disclosed: 2025-11-17 13:08:04
πŸ“ Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
πŸ“‚ Report JSON File: 3417162
@hackeronereports
❀1
🎯 New Report #3027461: Bypass of Cloudflare's Cache Keys and WAF via header overflow
πŸ”ΊSeverity: High
πŸ‘½ Reporter: david96
⭐️ Reputation: 3516
πŸ›  State: resolved
πŸ’Ό Team: Cloudflare Public Bug Bounty
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-03-12
⏰ Disclosed: 2025-11-18 08:08:43
πŸ“ Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
πŸ“‚ Report JSON File: 3027461
@hackeronereports
🎯 New Report #3431180: Double free in tool ssls load()
πŸ”ΊSeverity: null
πŸ‘½ Reporter: xkernel
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-18
⏰ Disclosed: 2025-11-18 23:32:00
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3431180
@hackeronereports
🎯 New Report #3404968: Stored-XSS in Banner Name field
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-30
⏰ Disclosed: 2025-11-19 09:36:35
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3404968
@hackeronereports
🎯 New Report #3403727: Reflected XSS in /admin/banner-zone.php (v6.0.0 )
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: vidang04
⭐️ Reputation: 121
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-29
⏰ Disclosed: 2025-11-19 09:36:08
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3403727
@hackeronereports
🎯 New Report #3403450: Information Disclosure via Verbose Error Messages
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-29
⏰ Disclosed: 2025-11-19 09:35:34
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3403450
@hackeronereports
🎯 New Report #3401612: IDOR Vulnerability in Banner Deletion
πŸ”ΊSeverity: High
πŸ‘½ Reporter: cyberjoker
⭐️ Reputation: 142
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-27
⏰ Disclosed: 2025-11-19 09:35:06
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3401612
@hackeronereports
🎯 New Report #3401464: Information Disclosure via β€œAdd user” lookup in Account Management (User Access)
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-27
⏰ Disclosed: 2025-11-19 09:34:36
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3401464
@hackeronereports
🎯 New Report #3400506: Stored XSS in Conversion Statistics via Tracker Name
πŸ”ΊSeverity: High
πŸ‘½ Reporter: cyberjoker
⭐️ Reputation: 142
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-26
⏰ Disclosed: 2025-11-19 09:33:37
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3400506
@hackeronereports