![]() |
|
HackerOne Disclosed Reports - 2026-10-05 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-10-05 (/Thread-HackerOne-Disclosed-Reports-2026-10-05) |
HackerOne disclosed reports - 2026-10-05 - hashXploiter - 10-06-2026
Medium
resolved HTML Injection in Contact Form Email Enables Phishing via Legitimate ████████ InfrastructureBug reported by Tenzai was disclosed at October 5, 2026, 11:34 am | Improper Output Neutralization for Logs An HTML injection vulnerability was discovered in a contact form email endpoint. The firstName field was rendered as unescaped HTML in transactional confirmation emails sent via SendGrid. Anchor tags with inline styles were not sanitized and persisted in email clients, allowing styled links to be injected into legitimate branded emails. The endpoint accepted requests without authentication, CAPTCHA, or rate limiting. Image tags were stripped by the email pipeline, but anchor tags survived with attacker-controlled styling and href attributes that were rewritten through SendGrid's click tracking proxy.
High
resolved Client-Side Denial of Service (DoS) via Memory Exhaustion on Password Reset EndpointBug reported by Dipesh Pokhrel was disclosed at October 5, 2026, 2:23 am | Uncontrolled Resource Consumption A client-side denial of service vulnerability was identified on a password reset endpoint. When the endpoint was accessed by an authenticated user, the browser automatically generated thousands of requests without user interaction, resulting in rapid memory exhaustion. The browser became unresponsive and crashed within minutes as memory usage continuously increased. |