![]() |
|
HackerOne Disclosed Reports - 2025-07-22 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-07-22 (/Thread-HackerOne-Disclosed-Reports-2025-07-22) |
HackerOne disclosed reports - 2025-07-22 - hashXploiter - 07-23-2025
High
resolved Mint Oauth2 access token for targeted userBug reported by Timothy Leung was disclosed at July 23, 2025, 12:06 am | Improper Authentication - Generic The vulnerability allowed a group owner to create an application that was trusted by default, bypassing CSRF controls for the authorization flow. This enabled the minting of access tokens for targeted users without their consent.
High
resolved XSS on Amazon Aquisition: elementalBug reported by Muhammad Qasim was disclosed at July 22, 2025, 12:48 am | Cross-site Scripting (XSS) - Reflected The XSS vulnerability on Amazon's acquisition of Elemental was identified and addressed. The summary provided a brief overview of the issue. |