![]() |
|
HackerOne Disclosed Reports - 2026-08-01 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-08-01 (/Thread-HackerOne-Disclosed-Reports-2026-08-01) |
HackerOne disclosed reports - 2026-08-01 - hashXploiter - 08-02-2026
Medium
resolved Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donatBug reported by Ali Khaled was disclosed at August 1, 2026, 12:27 pm | A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the payment, and ignored the donor's current privacy settings as well as the recipient's opt-in gate. This resulted in the exposure of donations that the donor had since made private or secret. |