HackerOne Disclosed Reports - 2025-05-08

0 Replies, 284 Views

Logo
Medium
resolved

Ability to access policy and updates for unauthorized program


Bug reported by was disclosed at May 8, 2025, 4:11 pm   |   Improper Access Control - Generic

The vulnerability allowed an unauthorized user to access the policy and updates for a restricted program using an API key. The user was able to retrieve sensitive data from the unauthorized program, even though they were only granted access to one of the two programs in the organization.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-05-08 - by hashXploiter - 05-09-2025, 06:00 PM



Users browsing this thread: 1 Guest(s)