π― New Report #3371414: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable Cloud)
πΊSeverity: Low
π½ Reporter: d0maxploit
βοΈ Reputation: 114
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-05
β° Disclosed: 2025-11-04 20:32:59
π Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
π Report JSON File: 3371414
@hackeronereports
πΊSeverity: Low
π½ Reporter: d0maxploit
βοΈ Reputation: 114
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-05
β° Disclosed: 2025-11-04 20:32:59
π Summary: A vulnerability was discovered where an account with the Editor role could call an API endpoint that disabled workspace-wide admin-only features. This was due to a lack of server-side role checks, allowing a vertical privilege escalation.
π Report JSON File: 3371414
@hackeronereports
π― New Report #3371448: Improper Authorization Leads to Editor can toggle admin-only workspace features (Lovable AI)
πΊSeverity: Low
π½ Reporter: d0maxploit
βοΈ Reputation: 114
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-05
β° Disclosed: 2025-11-04 22:54:23
π Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
π Report JSON File: 3371448
@hackeronereports
πΊSeverity: Low
π½ Reporter: d0maxploit
βοΈ Reputation: 114
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-05
β° Disclosed: 2025-11-04 22:54:23
π Summary: The API endpoint /workspaces/<WORKSPACE ID>/tool-preferences/ai gateway/enable did not enforce proper authorization checks. As a result, an account with the Editor role was able to disable the workspace-wide admin-only Lovable AI feature, which powers key AI functionalities across the workspace.
π Report JSON File: 3371448
@hackeronereports
π― New Report #3355218: CVE-2025-10966: missing SFTP host verification with wolfSSH
πΊSeverity: Low
π½ Reporter: giant anteater
βοΈ Reputation: 123
π State: resolved
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-09-23
β° Disclosed: 2025-11-05 21:57:54
π Summary: null
π Report JSON File: 3355218
@hackeronereports
πΊSeverity: Low
π½ Reporter: giant anteater
βοΈ Reputation: 123
π State: resolved
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-09-23
β° Disclosed: 2025-11-05 21:57:54
π Summary: null
π Report JSON File: 3355218
@hackeronereports
π― New Report #3335709: SQL Injection in Django ORM via Unvalidated ` connector` in Q Objects
πΊSeverity: Critical
π½ Reporter: cyberstan
βοΈ Reputation: 92
π State: resolved
πΌ Team: Django
π΅ Bounty: null
π Submitted: 2025-09-12
β° Disclosed: 2025-11-06 21:09:42
π Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
π Report JSON File: 3335709
@hackeronereports
πΊSeverity: Critical
π½ Reporter: cyberstan
βοΈ Reputation: 92
π State: resolved
πΌ Team: Django
π΅ Bounty: null
π Submitted: 2025-09-12
β° Disclosed: 2025-11-06 21:09:42
π Summary: A critical SQL injection vulnerability was discovered in the Django ORM's handling of Q objects. The internal WhereNode.as sql method used unsafe string formatting to inject the query connector, which could be controlled by an attacker through the connector key when creating a Q object. This allowed arbitrary SQL to be injected into the WHERE clause, bypassing the ORM's parameterization safeguards.
π Report JSON File: 3335709
@hackeronereports
π― New Report #3369843: Low-privileged user can enable or disable Lovable AI for new projects in workspace
πΊSeverity: Low
π½ Reporter: anxioussick
βοΈ Reputation: 129
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-03
β° Disclosed: 2025-11-07 03:52:10
π Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
π Report JSON File: 3369843
@hackeronereports
πΊSeverity: Low
π½ Reporter: anxioussick
βοΈ Reputation: 129
π State: resolved
πΌ Team: Lovable VDP
π΅ Bounty: null
π Submitted: 2025-10-03
β° Disclosed: 2025-11-07 03:52:10
π Summary: A vulnerability was discovered that allowed low-privileged users to enable or disable Lovable AI for new projects in a workspace. The vulnerability was caused by improper authorization, which enabled low-privileged users to modify the Lovable AI settings by replaying certain API endpoints.
π Report JSON File: 3369843
@hackeronereports
π― New Report #3378635: Unauthorized Password Reset Allows Account Takeover Across Tenant Boundaries
πΊSeverity: High
π½ Reporter: mcdave
βοΈ Reputation: 107
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-10-10
β° Disclosed: 2025-11-07 09:33:24
π Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
π Report JSON File: 3378635
@hackeronereports
πΊSeverity: High
π½ Reporter: mcdave
βοΈ Reputation: 107
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-10-10
β° Disclosed: 2025-11-07 09:33:24
π Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
π Report JSON File: 3378635
@hackeronereports
π― New Report #3414088: SMTP CRLF Command Injection in CURLOPT MAIL FROM and CURLOPT MAIL RCPT
πΊSeverity: Medium
π½ Reporter: bau1u
βοΈ Reputation: 116
π State: duplicate
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-06
β° Disclosed: 2025-11-10 10:39:03
π Summary: null
π Report JSON File: 3414088
@hackeronereports
πΊSeverity: Medium
π½ Reporter: bau1u
βοΈ Reputation: 116
π State: duplicate
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-06
β° Disclosed: 2025-11-10 10:39:03
π Summary: null
π Report JSON File: 3414088
@hackeronereports
π― New Report #3417428: libcurl MQTT `CURLOPT POSTFIELDSIZE LARGE` overflow leads to immediate DoS
πΊSeverity: Medium
π½ Reporter: jiyong
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-09
β° Disclosed: 2025-11-10 15:00:34
π Summary: null
π Report JSON File: 3417428
@hackeronereports
πΊSeverity: Medium
π½ Reporter: jiyong
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-09
β° Disclosed: 2025-11-10 15:00:34
π Summary: null
π Report JSON File: 3417428
@hackeronereports
π― New Report #3079738: Two click Account Takeover
πΊSeverity: High
π½ Reporter: fr4via
βοΈ Reputation: 11240
π State: resolved
πΌ Team: Basecamp
π΅ Bounty: null
π Submitted: 2025-04-06
β° Disclosed: 2025-11-11 09:14:15
π Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
π Report JSON File: 3079738
@hackeronereports
πΊSeverity: High
π½ Reporter: fr4via
βοΈ Reputation: 11240
π State: resolved
πΌ Team: Basecamp
π΅ Bounty: null
π Submitted: 2025-04-06
β° Disclosed: 2025-11-11 09:14:15
π Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
π Report JSON File: 3079738
@hackeronereports
π― New Report #3419636: Authentication Token Theft via Open Redirect in Callback URL Parameter
πΊSeverity: Critical
π½ Reporter: sle3pyhead
βοΈ Reputation: 96
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-11-11
β° Disclosed: 2025-11-14 15:26:16
π Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
π Report JSON File: 3419636
@hackeronereports
πΊSeverity: Critical
π½ Reporter: sle3pyhead
βοΈ Reputation: 96
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-11-11
β° Disclosed: 2025-11-14 15:26:16
π Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
π Report JSON File: 3419636
@hackeronereports
π― New Report #3382796: Responsible disclosure - public S3 bucket exposing JSON/config files
πΊSeverity: Low
π½ Reporter: xtawb
βοΈ Reputation: 29
π State: resolved
πΌ Team: AWS VDP
π΅ Bounty: null
π Submitted: 2025-10-14
β° Disclosed: 2025-11-14 19:25:28
π Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
π Report JSON File: 3382796
@hackeronereports
πΊSeverity: Low
π½ Reporter: xtawb
βοΈ Reputation: 29
π State: resolved
πΌ Team: AWS VDP
π΅ Bounty: null
π Submitted: 2025-10-14
β° Disclosed: 2025-11-14 19:25:28
π Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
π Report JSON File: 3382796
@hackeronereports
π― New Report #3427670: Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash
πΊSeverity: null
π½ Reporter: xkernel
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-16
β° Disclosed: 2025-11-16 22:40:20
π Summary: null
π Report JSON File: 3427670
@hackeronereports
πΊSeverity: null
π½ Reporter: xkernel
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-16
β° Disclosed: 2025-11-16 22:40:20
π Summary: null
π Report JSON File: 3427670
@hackeronereports
π― New Report #3417162: Authentication Bypass in Subscription Management Endpoint
πΊSeverity: Critical
π½ Reporter: 0hmz
βοΈ Reputation: 135
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-11-09
β° Disclosed: 2025-11-17 13:08:04
π Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
π Report JSON File: 3417162
@hackeronereports
πΊSeverity: Critical
π½ Reporter: 0hmz
βοΈ Reputation: 135
π State: resolved
πΌ Team: lemlist
π΅ Bounty: null
π Submitted: 2025-11-09
β° Disclosed: 2025-11-17 13:08:04
π Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
π Report JSON File: 3417162
@hackeronereports
β€1
π― New Report #3027461: Bypass of Cloudflare's Cache Keys and WAF via header overflow
πΊSeverity: High
π½ Reporter: david96
βοΈ Reputation: 3516
π State: resolved
πΌ Team: Cloudflare Public Bug Bounty
π΅ Bounty: null
π Submitted: 2025-03-12
β° Disclosed: 2025-11-18 08:08:43
π Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
π Report JSON File: 3027461
@hackeronereports
πΊSeverity: High
π½ Reporter: david96
βοΈ Reputation: 3516
π State: resolved
πΌ Team: Cloudflare Public Bug Bounty
π΅ Bounty: null
π Submitted: 2025-03-12
β° Disclosed: 2025-11-18 08:08:43
π Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
π Report JSON File: 3027461
@hackeronereports
π― New Report #3431180: Double free in tool ssls load()
πΊSeverity: null
π½ Reporter: xkernel
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-18
β° Disclosed: 2025-11-18 23:32:00
π Summary: null
π Report JSON File: 3431180
@hackeronereports
πΊSeverity: null
π½ Reporter: xkernel
βοΈ Reputation: 100
π State: informative
πΌ Team: curl
π΅ Bounty: null
π Submitted: 2025-11-18
β° Disclosed: 2025-11-18 23:32:00
π Summary: null
π Report JSON File: 3431180
@hackeronereports
π― New Report #3404968: Stored-XSS in Banner Name field
πΊSeverity: Low
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-30
β° Disclosed: 2025-11-19 09:36:35
π Summary: null
π Report JSON File: 3404968
@hackeronereports
πΊSeverity: Low
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-30
β° Disclosed: 2025-11-19 09:36:35
π Summary: null
π Report JSON File: 3404968
@hackeronereports
π― New Report #3403727: Reflected XSS in /admin/banner-zone.php (v6.0.0 )
πΊSeverity: Medium
π½ Reporter: vidang04
βοΈ Reputation: 121
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-29
β° Disclosed: 2025-11-19 09:36:08
π Summary: null
π Report JSON File: 3403727
@hackeronereports
πΊSeverity: Medium
π½ Reporter: vidang04
βοΈ Reputation: 121
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-29
β° Disclosed: 2025-11-19 09:36:08
π Summary: null
π Report JSON File: 3403727
@hackeronereports
π― New Report #3403450: Information Disclosure via Verbose Error Messages
πΊSeverity: Medium
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-29
β° Disclosed: 2025-11-19 09:35:34
π Summary: null
π Report JSON File: 3403450
@hackeronereports
πΊSeverity: Medium
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-29
β° Disclosed: 2025-11-19 09:35:34
π Summary: null
π Report JSON File: 3403450
@hackeronereports
π― New Report #3401612: IDOR Vulnerability in Banner Deletion
πΊSeverity: High
π½ Reporter: cyberjoker
βοΈ Reputation: 142
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-27
β° Disclosed: 2025-11-19 09:35:06
π Summary: null
π Report JSON File: 3401612
@hackeronereports
πΊSeverity: High
π½ Reporter: cyberjoker
βοΈ Reputation: 142
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-27
β° Disclosed: 2025-11-19 09:35:06
π Summary: null
π Report JSON File: 3401612
@hackeronereports
π― New Report #3401464: Information Disclosure via βAdd userβ lookup in Account Management (User Access)
πΊSeverity: Medium
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-27
β° Disclosed: 2025-11-19 09:34:36
π Summary: null
π Report JSON File: 3401464
@hackeronereports
πΊSeverity: Medium
π½ Reporter: yoyomiski
βοΈ Reputation: 303
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-27
β° Disclosed: 2025-11-19 09:34:36
π Summary: null
π Report JSON File: 3401464
@hackeronereports
π― New Report #3400506: Stored XSS in Conversion Statistics via Tracker Name
πΊSeverity: High
π½ Reporter: cyberjoker
βοΈ Reputation: 142
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-26
β° Disclosed: 2025-11-19 09:33:37
π Summary: null
π Report JSON File: 3400506
@hackeronereports
πΊSeverity: High
π½ Reporter: cyberjoker
βοΈ Reputation: 142
π State: resolved
πΌ Team: Revive Adserver
π΅ Bounty: null
π Submitted: 2025-10-26
β° Disclosed: 2025-11-19 09:33:37
π Summary: null
π Report JSON File: 3400506
@hackeronereports