![]() |
|
HackerOne Disclosed Reports - 2025-02-21 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-02-21 (/Thread-HackerOne-Disclosed-Reports-2025-02-21) |
HackerOne disclosed reports - 2025-02-21 - hashXploiter - 02-22-2025
Medium
resolved User Email Disclosure via ID-Based InvitationBug reported by Mohamed Kamal was disclosed at February 22, 2025, 2:13 am | Information Disclosure The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the privacy settings and led to unintended email exposure.
High
resolved Insecure Direct Object Reference (IDOR) in GraphQL deleteProfileImages MutationBug reported by AlphaHacks was disclosed at February 21, 2025, 10:18 pm | Insecure Direct Object Reference (IDOR) The Insecure Direct Object Reference (IDOR) vulnerability was discovered in the GraphQL deleteProfileImages mutation of the Autodesk User Profile. The vulnerability could have allowed an attacker to delete another user's photo through the "id" parameter. Autodesk has addressed the vulnerability.
Low
resolved Possible to enumerate valid files in password protected shares/files drop shares as well as spam folder with filesBug reported by Lukas Reschke was disclosed at February 21, 2025, 10:39 am | Information Disclosure The summary is as follows: |