![]() |
|
HackerOne Disclosed Reports - 2026-01-18 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-01-18 (/Thread-HackerOne-Disclosed-Reports-2026-01-18) |
HackerOne disclosed reports - 2026-01-18 - hashXploiter - 01-19-2026
Medium
resolved Disclose Hidden Comments on Media Section of hub.vroid.comBug reported by Giwa was disclosed at January 18, 2026, 11:24 am | Insecure Direct Object Reference (IDOR) A vulnerability was discovered in the Media section of the website where hidden comments could be disclosed. By intercepting a request to like a specific comment, the attacker was able to retrieve the content of the hidden comment, which should have only been visible to the original poster.
Low
resolved clickjacing can lead to account takeoverBug reported by ryu kanzake was disclosed at January 18, 2026, 11:21 am | UI Redressing (Clickjacking) An endpoint on the website You are not allowed to view links. Register or Login to view. was discovered to be vulnerable to clickjacking. Proof-of-concept code was provided to demonstrate how a user could be tricked into performing unintended actions on the website. |