Dark C0d3rs
HackerOne Disclosed Reports - 2026-03-04 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-03-04 (/Thread-HackerOne-Disclosed-Reports-2026-03-04)



HackerOne disclosed reports - 2026-03-04 - hashXploiter - 03-05-2026

Logo
High
resolved

Missing Access Control in MigrationFile allows attacker to upload files to any Migration


Bug reported by ahacker1 was disclosed at March 5, 2026, 2:23 am   |   Insecure Direct Object Reference (IDOR)

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized content to be uploaded to a user's repository migration export due to a missing authorization check in the repository migration upload endpoint. The vulnerability could be exploited by supplying the migration identifier to overwrite or replace a victim's migration archive.