HackerOne Disclosed Reports - 2026-08-27

0 Replies, 8 Views

Logo
Critical
resolved

Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)


Bug reported by Mattéo was disclosed at August 27, 2026, 7:35 am   |   Cross-site Scripting (XSS) - Stored

A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed in their authenticated session, enabling potential account takeover and other attacks. Multiple stacked vulnerabilities, including lack of input sanitization and authorization checks, were identified.


Logo
Critical
resolved

Critical SQL Injection WDM API (████████)


Bug reported by Mattéo was disclosed at August 27, 2026, 7:23 am   |   SQL Injection

A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)