HackerOne Disclosed Reports - 2026-03-27

0 Replies, 31 Views

Logo
Low
resolved

Password Strength Policy Bypass via Server-Side Validation Flaw


Bug reported by was disclosed at March 27, 2026, 7:49 pm   |   Business Logic Errors

A password strength policy bypass was discovered due to a server-side validation flaw. The password strength policy was only enforced in the browser, not on the server side.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-03-27 - by hashXploiter - 03-28-2026, 12:30 PM



Users browsing this thread: 1 Guest(s)