Hackerone Reports
227 subscribers
744 links
Last Check 2026-09-20 23:45:01
Download Telegram
🎯 New Report #3378635: Unauthorized Password Reset Allows Account Takeover Across Tenant Boundaries
πŸ”ΊSeverity: High
πŸ‘½ Reporter: mcdave
⭐️ Reputation: 107
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-10
⏰ Disclosed: 2025-11-07 09:33:24
πŸ“ Summary: An authorization issue was discovered in the application that allowed a tenant admin to change the password of another user within the same tenant, including invited agency accounts. The victim had to first accept the invitation before the attacker could proceed. The issue could allow unintended account access within a shared tenant environment, but multi-factor authentication successfully prevented logins when enabled. The issue was reported to the vendor and addressed to ensure stricter access controls for user credential changes.
πŸ“‚ Report JSON File: 3378635
@hackeronereports
🎯 New Report #3414088: SMTP CRLF Command Injection in CURLOPT MAIL FROM and CURLOPT MAIL RCPT
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: bau1u
⭐️ Reputation: 116
πŸ›  State: duplicate
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-06
⏰ Disclosed: 2025-11-10 10:39:03
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3414088
@hackeronereports
🎯 New Report #3417428: libcurl MQTT `CURLOPT POSTFIELDSIZE LARGE` overflow leads to immediate DoS
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: jiyong
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-09
⏰ Disclosed: 2025-11-10 15:00:34
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3417428
@hackeronereports
🎯 New Report #3079738: Two click Account Takeover
πŸ”ΊSeverity: High
πŸ‘½ Reporter: fr4via
⭐️ Reputation: 11240
πŸ›  State: resolved
πŸ’Ό Team: Basecamp
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-04-06
⏰ Disclosed: 2025-11-11 09:14:15
πŸ“ Summary: A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.
πŸ“‚ Report JSON File: 3079738
@hackeronereports
🎯 New Report #3419636: Authentication Token Theft via Open Redirect in Callback URL Parameter
πŸ”ΊSeverity: Critical
πŸ‘½ Reporter: sle3pyhead
⭐️ Reputation: 96
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-11
⏰ Disclosed: 2025-11-14 15:26:16
πŸ“ Summary: A vulnerability was identified in the email signup flow of a website that enabled authentication token theft through manipulation of the callback URL parameter. The vulnerability occurred when an attacker modified the callbackUrl parameter during the email signup process to point to an attacker-controlled domain. When a victim completed the email verification process by clicking the verification link, they were redirected to the malicious domain along with their authentication tokens. The redirection happened automatically as part of the normal signup flow. The vulnerability was caused by insufficient validation of the callback URL parameter and leveraged the trust users place in legitimate verification emails.
πŸ“‚ Report JSON File: 3419636
@hackeronereports
🎯 New Report #3382796: Responsible disclosure - public S3 bucket exposing JSON/config files
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: xtawb
⭐️ Reputation: 29
πŸ›  State: resolved
πŸ’Ό Team: AWS VDP
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-14
⏰ Disclosed: 2025-11-14 19:25:28
πŸ“ Summary: A publicly listable S3 bucket was discovered, exposing various JSON and configuration files. The bucket listing and file metadata were retrievable without authentication.
πŸ“‚ Report JSON File: 3382796
@hackeronereports
🎯 New Report #3427670: Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash
πŸ”ΊSeverity: null
πŸ‘½ Reporter: xkernel
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-16
⏰ Disclosed: 2025-11-16 22:40:20
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3427670
@hackeronereports
🎯 New Report #3417162: Authentication Bypass in Subscription Management Endpoint
πŸ”ΊSeverity: Critical
πŸ‘½ Reporter: 0hmz
⭐️ Reputation: 135
πŸ›  State: resolved
πŸ’Ό Team: lemlist
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-09
⏰ Disclosed: 2025-11-17 13:08:04
πŸ“ Summary: A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.
πŸ“‚ Report JSON File: 3417162
@hackeronereports
❀1
🎯 New Report #3027461: Bypass of Cloudflare's Cache Keys and WAF via header overflow
πŸ”ΊSeverity: High
πŸ‘½ Reporter: david96
⭐️ Reputation: 3516
πŸ›  State: resolved
πŸ’Ό Team: Cloudflare Public Bug Bounty
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-03-12
⏰ Disclosed: 2025-11-18 08:08:43
πŸ“ Summary: A limitation in the HTTP request header parsing in Front Line (FL) processing enabled attackers to bypass defined rulesets. The maximum amount of headers being parsed by openresty was 100 HTTP headers including internal ones. This problem applied to any ruleset on HTTP headers. Attackers were able to bypass WAF rules and perform cache forcing/poisoning. A global rule was implemented to block when too many headers were provided, which was recommended to be enabled. The length problem of parsed HTTP headers was mitigated with the rollout of the new Front Line implementation.
πŸ“‚ Report JSON File: 3027461
@hackeronereports
🎯 New Report #3431180: Double free in tool ssls load()
πŸ”ΊSeverity: null
πŸ‘½ Reporter: xkernel
⭐️ Reputation: 100
πŸ›  State: informative
πŸ’Ό Team: curl
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-18
⏰ Disclosed: 2025-11-18 23:32:00
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3431180
@hackeronereports
🎯 New Report #3404968: Stored-XSS in Banner Name field
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-30
⏰ Disclosed: 2025-11-19 09:36:35
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3404968
@hackeronereports
🎯 New Report #3403727: Reflected XSS in /admin/banner-zone.php (v6.0.0 )
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: vidang04
⭐️ Reputation: 121
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-29
⏰ Disclosed: 2025-11-19 09:36:08
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3403727
@hackeronereports
🎯 New Report #3403450: Information Disclosure via Verbose Error Messages
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-29
⏰ Disclosed: 2025-11-19 09:35:34
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3403450
@hackeronereports
🎯 New Report #3401612: IDOR Vulnerability in Banner Deletion
πŸ”ΊSeverity: High
πŸ‘½ Reporter: cyberjoker
⭐️ Reputation: 142
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-27
⏰ Disclosed: 2025-11-19 09:35:06
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3401612
@hackeronereports
🎯 New Report #3401464: Information Disclosure via β€œAdd user” lookup in Account Management (User Access)
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-27
⏰ Disclosed: 2025-11-19 09:34:36
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3401464
@hackeronereports
🎯 New Report #3400506: Stored XSS in Conversion Statistics via Tracker Name
πŸ”ΊSeverity: High
πŸ‘½ Reporter: cyberjoker
⭐️ Reputation: 142
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-26
⏰ Disclosed: 2025-11-19 09:33:37
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3400506
@hackeronereports
🎯 New Report #3399809: Stored XSS on inventory-retrieve.php
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: lu3ky-13
⭐️ Reputation: 17159
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-25
⏰ Disclosed: 2025-11-19 09:33:09
πŸ“ Summary: A Cross-site Scripting (XSS) vulnerability was discovered on the inventory-retrieve.php and campaign-edit.php pages. The vulnerability allowed an attacker to inject malicious code that would be executed when the page was loaded.
πŸ“‚ Report JSON File: 3399809
@hackeronereports
🎯 New Report #3399218: Improper sanitisation of input in the settings could cause DoS
πŸ”ΊSeverity: Low
πŸ‘½ Reporter: lu3ky-13
⭐️ Reputation: 17159
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-25
⏰ Disclosed: 2025-11-19 09:32:50
πŸ“ Summary: A vulnerability was found in the settings functionality of the application where attacker-controlled values in the email fromName and email fromCompany fields were persisted and later rendered to pages without proper output encoding. This could have led to the execution of arbitrary JavaScript in the context of the application, potentially disrupting or replacing the page UI and effectively disabling the site for affected users.
πŸ“‚ Report JSON File: 3399218
@hackeronereports
🎯 New Report #3399191: Reflected XSS in account-preferences-plugin.php
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: lu3ky-13
⭐️ Reputation: 17159
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-25
⏰ Disclosed: 2025-11-19 09:32:33
πŸ“ Summary: A reflected cross-site scripting (XSS) vulnerability was discovered in the account-preferences-plugin.php file of the Revive Adserver 6.0.1 application. Untrusted input from the "group" query parameter was reflected without proper output encoding or context-aware escaping, allowing the injection of malicious JavaScript code into the resulting page.
πŸ“‚ Report JSON File: 3399191
@hackeronereports
🎯 New Report #3398283: Authorization bypass allows changing email address of other users
πŸ”ΊSeverity: High
πŸ‘½ Reporter: yoyomiski
⭐️ Reputation: 303
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-10-24
⏰ Disclosed: 2025-11-19 09:32:13
πŸ“ Summary: The Revive Adserver 6.0.0 was found to have an authorization bypass vulnerability that allowed changing the email address of other users without requiring the account password. The vulnerability was present in the admin panel endpoint /admin/agency-user.php, which accepted a POST request that updated a user's email without re-authentication.
πŸ“‚ Report JSON File: 3398283
@hackeronereports
🎯 New Report #3413890: Unrestricted setPerPage allows huge result sets / resource exhaustion / mass log retrieval
πŸ”ΊSeverity: Medium
πŸ‘½ Reporter: vidang04
⭐️ Reputation: 121
πŸ›  State: resolved
πŸ’Ό Team: Revive Adserver
πŸ’΅ Bounty: null
πŸ• Submitted: 2025-11-06
⏰ Disclosed: 2025-11-19 13:00:00
πŸ“ Summary: null
πŸ“‚ Report JSON File: 3413890
@hackeronereports