Dark C0d3rs
HackerOne Disclosed Reports - 2026-01-18 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-01-18 (/Thread-HackerOne-Disclosed-Reports-2026-01-18)



HackerOne disclosed reports - 2026-01-18 - hashXploiter - 01-19-2026

Logo
Medium
resolved

Disclose Hidden Comments on Media Section of hub.vroid.com


Bug reported by Giwa was disclosed at January 18, 2026, 11:24 am   |   Insecure Direct Object Reference (IDOR)

A vulnerability was discovered in the Media section of the website where hidden comments could be disclosed. By intercepting a request to like a specific comment, the attacker was able to retrieve the content of the hidden comment, which should have only been visible to the original poster.


Logo
Low
resolved

clickjacing can lead to account takeover


Bug reported by ryu kanzake was disclosed at January 18, 2026, 11:21 am   |   UI Redressing (Clickjacking)

An endpoint on the website You are not allowed to view links. Register or Login to view. was discovered to be vulnerable to clickjacking. Proof-of-concept code was provided to demonstrate how a user could be tricked into performing unintended actions on the website.