HackerOne Disclosed Reports - 2026-10-05

0 Replies, 10 Views

Logo
Medium
resolved

HTML Injection in Contact Form Email Enables Phishing via Legitimate ████████ Infrastructure


Bug reported by Tenzai was disclosed at October 5, 2026, 11:34 am   |   Improper Output Neutralization for Logs

An HTML injection vulnerability was discovered in a contact form email endpoint. The firstName field was rendered as unescaped HTML in transactional confirmation emails sent via SendGrid. Anchor tags with inline styles were not sanitized and persisted in email clients, allowing styled links to be injected into legitimate branded emails. The endpoint accepted requests without authentication, CAPTCHA, or rate limiting. Image tags were stripped by the email pipeline, but anchor tags survived with attacker-controlled styling and href attributes that were rewritten through SendGrid's click tracking proxy.


Logo
High
resolved

Client-Side Denial of Service (DoS) via Memory Exhaustion on Password Reset Endpoint


Bug reported by Dipesh Pokhrel was disclosed at October 5, 2026, 2:23 am   |   Uncontrolled Resource Consumption

A client-side denial of service vulnerability was identified on a password reset endpoint. When the endpoint was accessed by an authenticated user, the browser automatically generated thousands of requests without user interaction, resulting in rapid memory exhaustion. The browser became unresponsive and crashed within minutes as memory usage continuously increased.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-10-05 - by hashXploiter - 10-06-2026, 12:30 PM



Users browsing this thread: 1 Guest(s)