![]() |
|
HackerOne Disclosed Reports - 2026-04-08 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-04-08 (/Thread-HackerOne-Disclosed-Reports-2026-04-08) |
HackerOne disclosed reports - 2026-04-08 - hashXploiter - 04-09-2026
Low
resolved wasResumeUsed ███ on /api-internal/api.htm endpoint leaking other user's resume usage statusBug reported by Raghav Phadke was disclosed at April 8, 2026, 7:32 pm | Improper Access Control - Generic The API endpoint that checks if a resume was used for previous job applications was found to be vulnerable. The endpoint accepted a parameter called "resumeMetadataId" which was not properly validated, allowing an attacker to check the usage status of resumes that did not belong to the user. This resulted in the leakage of other users' resume usage status.
Medium
resolved Account TakeoverBug reported by Abdulrahman Makki was disclosed at April 8, 2026, 7:30 pm | Improper Authentication - Generic A user's access token from a Facebook/Google app was found to be accepted by the target application, allowing for account takeover. The token was not properly validated, enabling the use of any previously obtained user token to log in to the application.
Low
resolved Open Redirect ████████Bug reported by Saurabh Patil was disclosed at April 8, 2026, 6:56 pm | Open Redirect The URL with the 'redirectUrl' parameter was found to be vulnerable to an open redirect attack. The parameter was not properly validated, allowing an attacker to redirect users to a malicious website of their choice. |