Dark C0d3rs
HackerOne Disclosed Reports - 2025-10-07 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2025-10-07 (/Thread-HackerOne-Disclosed-Reports-2025-10-07)



HackerOne disclosed reports - 2025-10-07 - hashXploiter - 10-08-2025

Logo
High
resolved

Pending invites remain valid even after the inviter is removed.


Bug reported by Mantosh Sah was disclosed at October 8, 2025, 3:51 am   |   Privilege Escalation

The pending invites created by a removed admin remained valid, and members already added by the removed admin remained in the team with admin privileges, even after the inviter was removed.