![]() |
|
HackerOne Disclosed Reports - 2026-09-30 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-09-30 (/Thread-HackerOne-Disclosed-Reports-2026-09-30) |
HackerOne disclosed reports - 2026-09-30 - hashXploiter - 10-01-2026
Critical
resolved IDOR allows user to access report details via reference.json endpointBug reported by sm41ldrag0n_mbbank was disclosed at October 1, 2026, 1:27 am | Insecure Direct Object Reference (IDOR) An information disclosure vulnerability was identified in a report details endpoint that allowed unauthorized users to access private report information. Despite the endpoint returning an access-denied error response, sensitive report details were inadvertently exposed in the error message body. The vulnerability was discovered through testing with standard user accounts and has since been fixed. No evidence of exploitation was found.
Medium
resolved SSRF via User-Controlled Push proxyServer in Notifications Push RegistrationBug reported by _dha was disclosed at September 30, 2026, 3:43 pm | Server-Side Request Forgery (SSRF) A server-side request forgery vulnerability was discovered in the notifications application version 5.0.0. An authenticated user with low privileges could register a push device with an attacker-controlled proxy server address through the push registration endpoint. When a notification was triggered for that user, the backend performed an outbound POST request to the attacker-specified proxy server address, allowing the backend to make HTTP requests to arbitrary destinations including internal services.
Medium
resolved Connector/J: malicious server crashes client JVM via unbounded result-set field-count allocation in ClientMessage.readPacketBug reported by Yalguun Tumenkhuu was disclosed at September 30, 2026, 8:00 am | Uncontrolled Resource Consumption MariaDB Connector/J was found to have an unbounded result-set field-count allocation vulnerability. When parsing result-set responses, the driver read the column count directly from the wire and used it to size a Java array without validation. A malicious server was able to declare an extremely large field count in a small packet, causing the client JVM to attempt a multi-gigabyte memory allocation and crash with OutOfMemoryError. The crash affected the entire JVM process, taking down all pooled connections and application threads. The vulnerability could be triggered at connection time during driver initialization, before any legitimate query execution and without requiring valid credentials. The driver's default plaintext mode made it susceptible to network-level attacks. |