HackerOne Disclosed Reports - 2026-04-16

0 Replies, 11 Views

Logo
Medium
resolved

Residual Malicious Payloads on HackerOne after Vulnerability Fixes


Bug reported by joejoe5 was disclosed at April 16, 2026, 12:06 pm   |   Improper Input Validation

A vulnerability was previously discovered on the HackerOne platform that allowed users to add malicious payloads to their profile pages. Despite remediation efforts, some of these malicious payloads were not fully removed from user profiles. This situation meant that the malicious content could still be triggered when users visited certain profile pages.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-04-16 - by hashXploiter - 04-17-2026, 12:30 PM



Users browsing this thread: 1 Guest(s)