Dark C0d3rs
HackerOne Disclosed Reports - 2025-05-08 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2025-05-08 (/Thread-HackerOne-Disclosed-Reports-2025-05-08)



HackerOne disclosed reports - 2025-05-08 - hashXploiter - 05-09-2025

Logo
Medium
resolved

Ability to access policy and updates for unauthorized program


Bug reported by was disclosed at May 8, 2025, 4:11 pm   |   Improper Access Control - Generic

The vulnerability allowed an unauthorized user to access the policy and updates for a restricted program using an API key. The user was able to retrieve sensitive data from the unauthorized program, even though they were only granted access to one of the two programs in the organization.