HackerOne Disclosed Reports - 2025-08-25

0 Replies, 214 Views

Logo
Low
resolved

AWS | Self Registration Internal LibreChat : Access to internal/proprietary LLMs


Bug reported by notnotnotveg was disclosed at August 25, 2025, 11:54 pm   |   Authentication Bypass Using an Alternate Path or Channel


Logo
High
resolved

Stored XSS in AREA tutorials


Bug reported by Ayush was disclosed at August 25, 2025, 12:39 pm   |   Cross-site Scripting (XSS) - Stored

A stored cross-site scripting (XSS) vulnerability was discovered in the AREA tutorials feature. The vulnerability could have allowed an attacker to inject malicious JavaScript code when publishing a tutorial. The vulnerability was reported and fixed by Autodesk.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-08-25 - by hashXploiter - 08-26-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)