HackerOne Disclosed Reports - 2025-10-22

0 Replies, 133 Views

Logo
Medium
resolved

Reflected Cross-Site Scripting (XSS) in Revive Adserver 5.5.2


Bug reported by Rabbit was disclosed at October 22, 2025, 9:54 am   |   Cross-site Scripting (XSS) - Reflected


Logo
Medium
resolved

2FA bypass possible on https://authsvc.singlestore.com


Bug reported by Axolot was disclosed at October 22, 2025, 6:44 am   |   Authentication Bypass

A vulnerability was discovered that allowed the 2FA authentication mechanism to be bypassed completely. An attacker could access the victim's account by only knowing the email address and password, without requiring the 2FA code.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-10-22 - by hashXploiter - 10-23-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)