HackerOne Disclosed Reports - 2025-07-22

0 Replies, 226 Views

Logo
High
resolved

Mint Oauth2 access token for targeted user


Bug reported by Timothy Leung was disclosed at July 23, 2025, 12:06 am   |   Improper Authentication - Generic

The vulnerability allowed a group owner to create an application that was trusted by default, bypassing CSRF controls for the authorization flow. This enabled the minting of access tokens for targeted users without their consent.


Logo
High
resolved

XSS on Amazon Aquisition: elemental


Bug reported by Muhammad Qasim was disclosed at July 22, 2025, 12:48 am   |   Cross-site Scripting (XSS) - Reflected

The XSS vulnerability on Amazon's acquisition of Elemental was identified and addressed. The summary provided a brief overview of the issue.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)