HackerOne Disclosed Reports - 2025-09-29

0 Replies, 165 Views

Logo
Medium
resolved

Information Exposure Through Directory Listing


Bug reported by Md. Farhad Ali was disclosed at September 29, 2025, 3:53 pm   |   Information Exposure Through Directory Listing

The web server was configured to display a list of files contained in the directory. This is not recommended as the directory may have contained files that were not normally exposed through links on the website.


Logo
Low
resolved

Email not verified when changing afterwards on apps.nextcloud.com


Bug reported by Md. Farhad Ali was disclosed at September 29, 2025, 3:50 pm   |   Violation of Secure Design Principles

The email verification bypass vulnerability was discovered in the web application apps.nextcloud.com. The vulnerability allowed attackers to create accounts with any email address without verification, effectively taking over victim accounts.


Logo
Medium
resolved

Exposing debug.log file leads to server full path disclosure


Bug reported by Md. Farhad Ali was disclosed at September 29, 2025, 3:50 pm   |   Business Logic Errors

The debug.log file on the nextcloud.com website was publicly accessible and contained sensitive information, including the server's full directory path. This type of information disclosure could have assisted attackers in understanding the internal structure of the server.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-09-29 - by hashXploiter - 09-30-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)