![]() |
|
HackerOne Disclosed Reports - 2025-04-06 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-04-06 (/Thread-HackerOne-Disclosed-Reports-2025-04-06) |
HackerOne disclosed reports - 2025-04-06 - hashXploiter - 04-07-2025
Medium
resolved Information disclouser from URL parameter "access" lead to Account TakeoverBug reported by Jovan was disclosed at April 7, 2025, 10:32 am | Information Disclosure The vulnerability allowed disclosure of sensitive information, such as JWT tokens, from URL parameters. These tokens could be used to gain unauthorized access to user accounts.
Low
resolved Disclosure of git metadata and springboot actuator informationBug reported by Juan Felipe Osorio Z was disclosed at April 7, 2025, 8:38 am | Information Disclosure The vulnerability involved the disclosure of git metadata and Springboot actuator information, which was responsibly disclosed and addressed through collaboration with the hacker. |