<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Dark C0d3rs - All Forums]]></title>
		<link>https://darkcoders.wiki/</link>
		<description><![CDATA[Dark C0d3rs - https://darkcoders.wiki]]></description>
		<pubDate>Tue, 23 Jun 2026 18:06:25 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-20]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-20</link>
			<pubDate>Sun, 21 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-20</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/134/e62a822e39ad039f23a0b89bfaaaf7bf97c5f11f_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723458' style='color: #4aa3ff;' target='new'>1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/farr?type=user' style='color: #4aa3ff;' target='new'> <strong> Duarte</strong></a> was disclosed at June 20, 2026, 3:58 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Khan Academy platform that allowed an attacker to achieve full account takeover of any user. The vulnerability was caused by an unescaped dot flaw in the regular expression used to validate redirect URLs. This allowed the attacker to register a malicious domain that passed the validation check, causing the victim's authentication token to be sent to the attacker's server. The attacker could then use this token to gain full access to the victim's account. The issue was addressed by escaping the dots in the regular expression. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/134/e62a822e39ad039f23a0b89bfaaaf7bf97c5f11f_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723458' style='color: #4aa3ff;' target='new'>1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/farr?type=user' style='color: #4aa3ff;' target='new'> <strong> Duarte</strong></a> was disclosed at June 20, 2026, 3:58 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Khan Academy platform that allowed an attacker to achieve full account takeover of any user. The vulnerability was caused by an unescaped dot flaw in the regular expression used to validate redirect URLs. This allowed the attacker to register a malicious domain that passed the validation check, causing the victim's authentication token to be sent to the attacker's server. The attacker could then use this token to gain full access to the victim's account. The issue was addressed by escaping the dots in the regular expression. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-18]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-18</link>
			<pubDate>Fri, 19 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-18</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3658225' style='color: #4aa3ff;' target='new'>HTTP/2 sessions never clean up after GOAWAY on invalid protocol errors</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pimterry?type=user' style='color: #4aa3ff;' target='new'> <strong> Tim Perry</strong></a> was disclosed at June 18, 2026, 5:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in the Node.js HTTP/2 server API was discovered that could cause servers to keep accepting data even after sending a GOAWAY frame. This vulnerability affected Node.js 22 and Node.js 24. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3692858' style='color: #4aa3ff;' target='new'>Permission Model Bypass via `process.report.writeReport()` Path Misvalidation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/suul?type=user' style='color: #4aa3ff;' target='new'> <strong> Joseph Semaan</strong></a> was disclosed at June 18, 2026, 2:48 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was discovered in the Node.js permission model that allowed bypassing of security controls via the `process.report.writeReport()` path misvalidation. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fjjiC5585s8WoDGHv2M5okbJ/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2509022' style='color: #4aa3ff;' target='new'>Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/saltymermaid?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 18, 2026, 12:48 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Reflected</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A reflected XSS vulnerability was reported in the AI chat bot greetings at help.shopify.com. The issue was caused by the rendering of a markdown image in the greeting, which allowed the attacker to inject a payload through the image URL. The vulnerability was addressed by removing the attacker-controlled greeting input path. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3658225' style='color: #4aa3ff;' target='new'>HTTP/2 sessions never clean up after GOAWAY on invalid protocol errors</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pimterry?type=user' style='color: #4aa3ff;' target='new'> <strong> Tim Perry</strong></a> was disclosed at June 18, 2026, 5:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in the Node.js HTTP/2 server API was discovered that could cause servers to keep accepting data even after sending a GOAWAY frame. This vulnerability affected Node.js 22 and Node.js 24. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3692858' style='color: #4aa3ff;' target='new'>Permission Model Bypass via `process.report.writeReport()` Path Misvalidation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/suul?type=user' style='color: #4aa3ff;' target='new'> <strong> Joseph Semaan</strong></a> was disclosed at June 18, 2026, 2:48 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was discovered in the Node.js permission model that allowed bypassing of security controls via the `process.report.writeReport()` path misvalidation. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fjjiC5585s8WoDGHv2M5okbJ/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2509022' style='color: #4aa3ff;' target='new'>Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/saltymermaid?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 18, 2026, 12:48 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Reflected</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A reflected XSS vulnerability was reported in the AI chat bot greetings at help.shopify.com. The issue was caused by the rendering of a markdown image in the greeting, which allowed the attacker to inject a payload through the image URL. The vulnerability was addressed by removing the attacker-controlled greeting input path. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-17]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-17</link>
			<pubDate>Thu, 18 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-17</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3694007' style='color: #4aa3ff;' target='new'>Authenticated Elasticsearch Painless script execution via Query.search.sort_query on hackerone.com/graphql</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/brumbelow?type=user' style='color: #4aa3ff;' target='new'> <strong> AB</strong></a> was disclosed at June 17, 2026, 2:17 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The GraphQL query on hackerone.com/graphql allowed authenticated users to execute arbitrary Painless scripts through the sort_query argument, without server-side validation or allowlisting. This was confirmed by submitting requests with different Painless script payloads, and observing that the script's return value determined the document ordering in the search results. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3694007' style='color: #4aa3ff;' target='new'>Authenticated Elasticsearch Painless script execution via Query.search.sort_query on hackerone.com/graphql</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/brumbelow?type=user' style='color: #4aa3ff;' target='new'> <strong> AB</strong></a> was disclosed at June 17, 2026, 2:17 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The GraphQL query on hackerone.com/graphql allowed authenticated users to execute arbitrary Painless scripts through the sort_query argument, without server-side validation or allowlisting. This was confirmed by submitting requests with different Painless script payloads, and observing that the script's return value determined the document ordering in the search results. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-16]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-16</link>
			<pubDate>Wed, 17 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-16</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3611837' style='color: #4aa3ff;' target='new'>Unauthenticated file deletion via deleteFileMessage DDP method allows permanent destruction of any uploaded file</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/eldudareeno?type=user' style='color: #4aa3ff;' target='new'> <strong> eldudarino</strong></a> was disclosed at June 16, 2026, 9:47 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3701692' style='color: #4aa3ff;' target='new'>Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/aptupdate?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 16, 2026, 7:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor's Conflux OOO queue accounting. The vulnerability could cause the global OOO queue byte counter to remain inflated after a Conflux set was torn down, even though the memory had already been freed. This was due to a lack of accounting updates during the teardown process. No sensitive information was included in the report. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3611837' style='color: #4aa3ff;' target='new'>Unauthenticated file deletion via deleteFileMessage DDP method allows permanent destruction of any uploaded file</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/eldudareeno?type=user' style='color: #4aa3ff;' target='new'> <strong> eldudarino</strong></a> was disclosed at June 16, 2026, 9:47 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3701692' style='color: #4aa3ff;' target='new'>Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/aptupdate?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 16, 2026, 7:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor's Conflux OOO queue accounting. The vulnerability could cause the global OOO queue byte counter to remain inflated after a Conflux set was torn down, even though the memory had already been freed. This was due to a lack of accounting updates during the teardown process. No sensitive information was included in the report. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-11]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-11</link>
			<pubDate>Fri, 12 Jun 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-11</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3558713' style='color: #4aa3ff;' target='new'>Command Injection via Unsanitized Bundling Options in `aws-cdk-lib/aws-lambda-nodejs`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/inkerton?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 11, 2026, 4:54 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3619288' style='color: #4aa3ff;' target='new'>RCE + PAT Exfiltration via pull_request_target in privacy-configuration/auto-respond-pr.yml — Direct Supply Chain to All DDG Browsers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/6r1ff1n?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at June 11, 2026, 2:30 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the "auto-respond-pr.yml" GitHub Actions workflow of the "privacy-configuration" repository. The workflow used the "pull_request_target" trigger, which checked out the fork's repository as both the "base" and "PR" branches. This allowed an attacker to control the code executed by the workflow, leading to arbitrary code execution and the exposure of the "PRIVACY_CONFIG_PAT" secret. The exposed token was likely used for PR auto-approval, enabling the attacker to approve their own PRs and access private repository contents. The vulnerability also resulted in the unconditional exposure of additional secrets, such as "ASANA_ACCESS_TOKEN" and "GH_RO_PAT", when a fork PR was closed. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3619287' style='color: #4aa3ff;' target='new'>RCE + Supply Chain Attack via pull_request_target in content-scope-scripts/semver-label.yml — Affects All DuckDuckGo Browsers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/6r1ff1n?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at June 11, 2026, 2:28 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the DuckDuckGo content-scope-scripts repository's GitHub Actions workflow. The workflow used the pull_request_target trigger without access controls, allowing untrusted code from fork pull requests to be checked out and executed. This could have led to remote code execution and the potential exfiltration of sensitive information, such as API keys, on the runner. The vulnerability also could have been exploited to manipulate the automated release pipeline, potentially compromising all DuckDuckGo browsers and extensions across multiple platforms. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3383079' style='color: #4aa3ff;' target='new'>SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at June 11, 2026, 11:52 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Rocket.Chat version 7.10.1 where the oEmbed feature did not properly validate redirected URLs. This allowed an attacker to bypass SSRF protections and access internal network resources that would otherwise be unreachable. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3393664' style='color: #4aa3ff;' target='new'>SSRF via improper validation after DNS name resolution in the link-preview feature</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at June 11, 2026, 11:52 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The link-preview feature in Rocket.Chat version 7.11.0 did not properly validate the IP address after DNS resolution. This allowed an attacker to obtain a domain that pointed to an internal IP address, triggering SSRF and enabling access to internal hosts that would otherwise be unreachable. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3558713' style='color: #4aa3ff;' target='new'>Command Injection via Unsanitized Bundling Options in `aws-cdk-lib/aws-lambda-nodejs`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/inkerton?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 11, 2026, 4:54 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3619288' style='color: #4aa3ff;' target='new'>RCE + PAT Exfiltration via pull_request_target in privacy-configuration/auto-respond-pr.yml — Direct Supply Chain to All DDG Browsers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/6r1ff1n?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at June 11, 2026, 2:30 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the "auto-respond-pr.yml" GitHub Actions workflow of the "privacy-configuration" repository. The workflow used the "pull_request_target" trigger, which checked out the fork's repository as both the "base" and "PR" branches. This allowed an attacker to control the code executed by the workflow, leading to arbitrary code execution and the exposure of the "PRIVACY_CONFIG_PAT" secret. The exposed token was likely used for PR auto-approval, enabling the attacker to approve their own PRs and access private repository contents. The vulnerability also resulted in the unconditional exposure of additional secrets, such as "ASANA_ACCESS_TOKEN" and "GH_RO_PAT", when a fork PR was closed. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3619287' style='color: #4aa3ff;' target='new'>RCE + Supply Chain Attack via pull_request_target in content-scope-scripts/semver-label.yml — Affects All DuckDuckGo Browsers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/6r1ff1n?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at June 11, 2026, 2:28 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the DuckDuckGo content-scope-scripts repository's GitHub Actions workflow. The workflow used the pull_request_target trigger without access controls, allowing untrusted code from fork pull requests to be checked out and executed. This could have led to remote code execution and the potential exfiltration of sensitive information, such as API keys, on the runner. The vulnerability also could have been exploited to manipulate the automated release pipeline, potentially compromising all DuckDuckGo browsers and extensions across multiple platforms. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3383079' style='color: #4aa3ff;' target='new'>SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at June 11, 2026, 11:52 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Rocket.Chat version 7.10.1 where the oEmbed feature did not properly validate redirected URLs. This allowed an attacker to bypass SSRF protections and access internal network resources that would otherwise be unreachable. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3393664' style='color: #4aa3ff;' target='new'>SSRF via improper validation after DNS name resolution in the link-preview feature</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at June 11, 2026, 11:52 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The link-preview feature in Rocket.Chat version 7.11.0 did not properly validate the IP address after DNS resolution. This allowed an attacker to obtain a domain that pointed to an internal IP address, triggering SSRF and enabling access to internal hosts that would otherwise be unreachable. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-09]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-09</link>
			<pubDate>Wed, 10 Jun 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-09</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2389431' style='color: #4aa3ff;' target='new'>Action Text ReDoS (Ruby 3.1  or lower)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ooooooo_q?type=user' style='color: #4aa3ff;' target='new'> <strong> ooooooo_q</strong></a> was disclosed at June 9, 2026, 4:37 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the ActionText component of the Rails web framework for Ruby versions 3.1 and lower. The vulnerability was caused by a Regular Expression Denial of Service (ReDoS) issue in the plain_text_for_blockquote_node method. This method was used in the ActionText::Fragment#to_plain_text functionality. The vulnerability could be triggered by crafting malicious text and calling the to_plain_text method. The vulnerability was resolved in later versions of Ruby. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2389431' style='color: #4aa3ff;' target='new'>Action Text ReDoS (Ruby 3.1  or lower)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ooooooo_q?type=user' style='color: #4aa3ff;' target='new'> <strong> ooooooo_q</strong></a> was disclosed at June 9, 2026, 4:37 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the ActionText component of the Rails web framework for Ruby versions 3.1 and lower. The vulnerability was caused by a Regular Expression Denial of Service (ReDoS) issue in the plain_text_for_blockquote_node method. This method was used in the ActionText::Fragment#to_plain_text functionality. The vulnerability could be triggered by crafting malicious text and calling the to_plain_text method. The vulnerability was resolved in later versions of Ruby. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-08]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-08</link>
			<pubDate>Tue, 09 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-08</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2389431' style='color: #4aa3ff;' target='new'>Action Text ReDoS (Ruby 3.1  or lower)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ooooooo_q?type=user' style='color: #4aa3ff;' target='new'> <strong> ooooooo_q</strong></a> was disclosed at June 9, 2026, 4:37 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the ActionText component of the Rails web framework for Ruby versions 3.1 and lower. The vulnerability was caused by a Regular Expression Denial of Service (ReDoS) issue in the plain_text_for_blockquote_node method. This method was used in the ActionText::Fragment#to_plain_text functionality. The vulnerability could be triggered by crafting malicious text and calling the to_plain_text method. The vulnerability was resolved in later versions of Ruby. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/2389431' style='color: #4aa3ff;' target='new'>Action Text ReDoS (Ruby 3.1  or lower)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ooooooo_q?type=user' style='color: #4aa3ff;' target='new'> <strong> ooooooo_q</strong></a> was disclosed at June 9, 2026, 4:37 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the ActionText component of the Rails web framework for Ruby versions 3.1 and lower. The vulnerability was caused by a Regular Expression Denial of Service (ReDoS) issue in the plain_text_for_blockquote_node method. This method was used in the ActionText::Fragment#to_plain_text functionality. The vulnerability could be triggered by crafting malicious text and calling the to_plain_text method. The vulnerability was resolved in later versions of Ruby. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-07]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-07</link>
			<pubDate>Mon, 08 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-07</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3483708' style='color: #4aa3ff;' target='new'>Valid share tokens allow to access tempory upload files of share owner</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pirikara?type=user' style='color: #4aa3ff;' target='new'> <strong> Pirikara</strong></a> was disclosed at June 7, 2026, 9:31 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered that allowed access to temporary upload files of a share owner using valid share tokens. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3489490' style='color: #4aa3ff;' target='new'>Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/priyanka010?type=user' style='color: #4aa3ff;' target='new'> <strong> priyanka chandrakar</strong></a> was disclosed at June 7, 2026, 9:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An authentication bypass vulnerability was discovered in the ID4me handling in the OIDC implementation. The vulnerability was caused by missing JWT signature verification for user authentication. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3625210' style='color: #4aa3ff;' target='new'>PIN bypass in PassCodeActivity via back button</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/alper_ozturk?type=user' style='color: #4aa3ff;' target='new'> <strong> Alper Öztürk</strong></a> was disclosed at June 7, 2026, 8:14 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the PassCodeActivity of a certain application. The vulnerability allowed bypassing the PIN code by pressing the back button. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3483708' style='color: #4aa3ff;' target='new'>Valid share tokens allow to access tempory upload files of share owner</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pirikara?type=user' style='color: #4aa3ff;' target='new'> <strong> Pirikara</strong></a> was disclosed at June 7, 2026, 9:31 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered that allowed access to temporary upload files of a share owner using valid share tokens. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3489490' style='color: #4aa3ff;' target='new'>Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/priyanka010?type=user' style='color: #4aa3ff;' target='new'> <strong> priyanka chandrakar</strong></a> was disclosed at June 7, 2026, 9:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An authentication bypass vulnerability was discovered in the ID4me handling in the OIDC implementation. The vulnerability was caused by missing JWT signature verification for user authentication. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3625210' style='color: #4aa3ff;' target='new'>PIN bypass in PassCodeActivity via back button</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/alper_ozturk?type=user' style='color: #4aa3ff;' target='new'> <strong> Alper Öztürk</strong></a> was disclosed at June 7, 2026, 8:14 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the PassCodeActivity of a certain application. The vulnerability allowed bypassing the PIN code by pressing the back button. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-05]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-05</link>
			<pubDate>Sat, 06 Jun 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-05</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/016/427/554594bb2f3fe33ee0f4971daf33bca27d1421d9_original./3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3355766' style='color: #4aa3ff;' target='new'>DLL side-loading vulnerability in Sony Music Center for PC Ver. 2.7.2 (Latest version)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/resurrect20?type=user' style='color: #4aa3ff;' target='new'> <strong> Suphawith Phusanbai</strong></a> was disclosed at June 5, 2026, 9:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Search Path Element</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A DLL side-loading vulnerability was discovered in Sony Music Center for PC Ver. 2.7.2. The application insecurely searched for a missing DLL file in the system PATH environment, allowing an attacker with access to the victim's local machine to achieve arbitrary code execution by placing a malicious DLL file in the PATH. The vulnerability was referenced in the MITRE ATT&CK framework. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/016/427/554594bb2f3fe33ee0f4971daf33bca27d1421d9_original./3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3355766' style='color: #4aa3ff;' target='new'>DLL side-loading vulnerability in Sony Music Center for PC Ver. 2.7.2 (Latest version)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/resurrect20?type=user' style='color: #4aa3ff;' target='new'> <strong> Suphawith Phusanbai</strong></a> was disclosed at June 5, 2026, 9:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Search Path Element</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A DLL side-loading vulnerability was discovered in Sony Music Center for PC Ver. 2.7.2. The application insecurely searched for a missing DLL file in the system PATH environment, allowing an attacker with access to the victim's local machine to achieve arbitrary code execution by placing a malicious DLL file in the PATH. The vulnerability was referenced in the MITRE ATT&CK framework. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-03]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-03</link>
			<pubDate>Thu, 04 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-03</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3650504' style='color: #4aa3ff;' target='new'>Missing access control when linking banners or campaigns to zones </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/darky_os?type=user' style='color: #4aa3ff;' target='new'> <strong> Ahmed Ghadban</strong></a> was disclosed at June 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A missing access control check was identified when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API. This could have allowed a low-privileged user to link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3650582' style='color: #4aa3ff;' target='new'>Missing access control when linking trackers to campaigns</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/darky_os?type=user' style='color: #4aa3ff;' target='new'> <strong> Ahmed Ghadban</strong></a> was disclosed at June 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A missing access control check was reported when linking trackers to campaigns through the "campaign-trackers.php" script of Revive Adserver 6.0.6 and earlier. A low-privileged user could link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3653196' style='color: #4aa3ff;' target='new'>Blind SQL injection via clientid parameter in zone‑include.php</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/titanrain?type=user' style='color: #4aa3ff;' target='new'> <strong> Kaushalendra Dubey</strong></a> was disclosed at June 3, 2026, 1:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>SQL Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3653316' style='color: #4aa3ff;' target='new'>Reflected XSS via clientid parameter in zone‑include.php</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/titanrain?type=user' style='color: #4aa3ff;' target='new'> <strong> Kaushalendra Dubey</strong></a> was disclosed at June 3, 2026, 1:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Reflected</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3656781' style='color: #4aa3ff;' target='new'>PHP code injection via delivery limitation logical </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x4c616e?type=user' style='color: #4aa3ff;' target='new'> <strong> 0x4C616E</strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3669623' style='color: #4aa3ff;' target='new'>Stored XSS via Full Name field in userlog email entries</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/3l4?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3672641' style='color: #4aa3ff;' target='new'>Session ID reuse allowing XML‑RPC API authentication bypass</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x4c616e?type=user' style='color: #4aa3ff;' target='new'> <strong> 0x4C616E</strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3677576' style='color: #4aa3ff;' target='new'>Missing access control when modifying parent entities via XML‑RPC</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/3l4?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 3, 2026, 1:32 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3678828' style='color: #4aa3ff;' target='new'>Banner status override by advertiser‑level users</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/v3rtical?type=user' style='color: #4aa3ff;' target='new'> <strong> Vertical</strong></a> was disclosed at June 3, 2026, 1:32 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in Revive Adserver 6.0.6 and earlier, which allowed an advertiser-level user to activate or deactivate a banner without proper permissions. The issue was caused by the banner-edit.php script, which allowed the banner status to be overwritten solely based on banner edit permissions. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3744200' style='color: #4aa3ff;' target='new'>PHP code injection via unexpected delivery limitation parameter</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/rajib_mahmud?type=user' style='color: #4aa3ff;' target='new'> <strong> rajib mahmud</strong></a> was disclosed at June 3, 2026, 1:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in Revive Adserver 6.0.6 and earlier versions where user input was not properly validated when saving delivery limitations. This allowed a low-privileged user to inject malicious PHP code into the `compiledlimitations` field, which could then be executed during banner delivery. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3650504' style='color: #4aa3ff;' target='new'>Missing access control when linking banners or campaigns to zones </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/darky_os?type=user' style='color: #4aa3ff;' target='new'> <strong> Ahmed Ghadban</strong></a> was disclosed at June 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A missing access control check was identified when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API. This could have allowed a low-privileged user to link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3650582' style='color: #4aa3ff;' target='new'>Missing access control when linking trackers to campaigns</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/darky_os?type=user' style='color: #4aa3ff;' target='new'> <strong> Ahmed Ghadban</strong></a> was disclosed at June 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A missing access control check was reported when linking trackers to campaigns through the "campaign-trackers.php" script of Revive Adserver 6.0.6 and earlier. A low-privileged user could link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3653196' style='color: #4aa3ff;' target='new'>Blind SQL injection via clientid parameter in zone‑include.php</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/titanrain?type=user' style='color: #4aa3ff;' target='new'> <strong> Kaushalendra Dubey</strong></a> was disclosed at June 3, 2026, 1:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>SQL Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3653316' style='color: #4aa3ff;' target='new'>Reflected XSS via clientid parameter in zone‑include.php</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/titanrain?type=user' style='color: #4aa3ff;' target='new'> <strong> Kaushalendra Dubey</strong></a> was disclosed at June 3, 2026, 1:34 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Reflected</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3656781' style='color: #4aa3ff;' target='new'>PHP code injection via delivery limitation logical </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x4c616e?type=user' style='color: #4aa3ff;' target='new'> <strong> 0x4C616E</strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3669623' style='color: #4aa3ff;' target='new'>Stored XSS via Full Name field in userlog email entries</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/3l4?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3672641' style='color: #4aa3ff;' target='new'>Session ID reuse allowing XML‑RPC API authentication bypass</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x4c616e?type=user' style='color: #4aa3ff;' target='new'> <strong> 0x4C616E</strong></a> was disclosed at June 3, 2026, 1:33 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3677576' style='color: #4aa3ff;' target='new'>Missing access control when modifying parent entities via XML‑RPC</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/3l4?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at June 3, 2026, 1:32 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3678828' style='color: #4aa3ff;' target='new'>Banner status override by advertiser‑level users</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/v3rtical?type=user' style='color: #4aa3ff;' target='new'> <strong> Vertical</strong></a> was disclosed at June 3, 2026, 1:32 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in Revive Adserver 6.0.6 and earlier, which allowed an advertiser-level user to activate or deactivate a banner without proper permissions. The issue was caused by the banner-edit.php script, which allowed the banner status to be overwritten solely based on banner edit permissions. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/002/367/4f47a5b4a364515d4bbdc17550d67ea5415363cd_original.png/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3744200' style='color: #4aa3ff;' target='new'>PHP code injection via unexpected delivery limitation parameter</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/rajib_mahmud?type=user' style='color: #4aa3ff;' target='new'> <strong> rajib mahmud</strong></a> was disclosed at June 3, 2026, 1:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in Revive Adserver 6.0.6 and earlier versions where user input was not properly validated when saving delivery limitations. This allowed a low-privileged user to inject malicious PHP code into the `compiledlimitations` field, which could then be executed during banner delivery. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[The AI Red Team Walkthrough:  From Jailbreaks to Agent Compromise]]></title>
			<link>https://darkcoders.wiki/Thread-The-AI-Red-Team-Walkthrough-From-Jailbreaks-to-Agent-Compromise</link>
			<pubDate>Wed, 03 Jun 2026 07:14:42 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-The-AI-Red-Team-Walkthrough-From-Jailbreaks-to-Agent-Compromise</guid>
			<description><![CDATA[<iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/z7PNJFol_l8" frameborder="0" allowfullscreen="true"></iframe>]]></description>
			<content:encoded><![CDATA[<iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/z7PNJFol_l8" frameborder="0" allowfullscreen="true"></iframe>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-02]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-02</link>
			<pubDate>Wed, 03 Jun 2026 07:00:05 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-02</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/nfgd330erfzkfvdi70dv3txlgpah/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3423013' style='color: #4aa3ff;' target='new'>page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/imnotr3al?type=user' style='color: #4aa3ff;' target='new'> <strong> Natthakul Raingoen</strong></a> was disclosed at June 2, 2026, 3:30 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An open redirect vulnerability was identified in page.line.me because redirect destinations were not properly restricted to trusted domains. This vulnerability could have been abused within an OAuth 2.0 authorization flow to cause the authorization response to be sent to an attacker-controlled endpoint, potentially exposing the authorization code issued after successful user authentication. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/nfgd330erfzkfvdi70dv3txlgpah/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3423013' style='color: #4aa3ff;' target='new'>page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/imnotr3al?type=user' style='color: #4aa3ff;' target='new'> <strong> Natthakul Raingoen</strong></a> was disclosed at June 2, 2026, 3:30 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An open redirect vulnerability was identified in page.line.me because redirect destinations were not properly restricted to trusted domains. This vulnerability could have been abused within an OAuth 2.0 authorization flow to cause the authorization response to be sent to an attacker-controlled endpoint, potentially exposing the authorization code issued after successful user authentication. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Certification Exam Opportunity 100% OFF: Certified LLM Security Professional (CLLMSP)]]></title>
			<link>https://darkcoders.wiki/Thread-Certification-Exam-Opportunity-100-OFF-Certified-LLM-Security-Professional-CLLMSP</link>
			<pubDate>Wed, 03 Jun 2026 06:33:40 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-Certification-Exam-Opportunity-100-OFF-Certified-LLM-Security-Professional-CLLMSP</guid>
			<description><![CDATA[Large Language Models are changing the way organizations build, automate, and secure technology. But with this innovation comes a new class of security risks, including prompt injection, jailbreaks, tool poisoning, insecure AI agents, RAG data leakage, shadow AI, and MCP security issues.<br />
<br />
The Certified LLM Security Professional (CLLMSP) exam was designed for professionals who want to understand, test, secure, and govern LLM-powered systems in real-world environments.<br />
<br />
This certification covers key areas such as:<br />
• LLM architecture and security fundamentals<br />
• OWASP Top 10 for LLMs<br />
• Jailbreak attacks and defenses<br />
• MCP security<br />
• AI agents and orchestration risks<br />
• AI governance, NIST AI RMF, ISO/IEC 42001, and EU AI Act<br />
• Data privacy and compliance<br />
• Secure AI-assisted development<br />
• Incident response for AI systems<br />
<br />
The exam includes 200 questions across 9 domains and is built for Security Engineers, AI/ML Engineers, Red Teamers, Pentesters, DevSecOps professionals, GRC teams, CISOs, and anyone working with AI security.<br />
<br />
Use the coupon below to take the exam for free:<br />
Coupon: <span style="font-weight: bold;" class="mycode_b">AISECURITYFORALL</span><br />
<br />
You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view.<br />
<br />
<img src="https://media.licdn.com/dms/image/v2/D4D22AQHjUsPYjtWQCg/feedshare-image-high-res/B4DZ6A03J0JcAY-/0/1780277802254?e=1782345600&amp;v=beta&amp;t=a34p-7-h_c-K1UkajAawWmfsgNVC913YAm2D1a0UiNw" loading="lazy"  alt="[Image: 1780277802254?e=1782345600&amp;v=beta&amp;t=a34p...m2D1a0UiNw]" class="mycode_img" />]]></description>
			<content:encoded><![CDATA[Large Language Models are changing the way organizations build, automate, and secure technology. But with this innovation comes a new class of security risks, including prompt injection, jailbreaks, tool poisoning, insecure AI agents, RAG data leakage, shadow AI, and MCP security issues.<br />
<br />
The Certified LLM Security Professional (CLLMSP) exam was designed for professionals who want to understand, test, secure, and govern LLM-powered systems in real-world environments.<br />
<br />
This certification covers key areas such as:<br />
• LLM architecture and security fundamentals<br />
• OWASP Top 10 for LLMs<br />
• Jailbreak attacks and defenses<br />
• MCP security<br />
• AI agents and orchestration risks<br />
• AI governance, NIST AI RMF, ISO/IEC 42001, and EU AI Act<br />
• Data privacy and compliance<br />
• Secure AI-assisted development<br />
• Incident response for AI systems<br />
<br />
The exam includes 200 questions across 9 domains and is built for Security Engineers, AI/ML Engineers, Red Teamers, Pentesters, DevSecOps professionals, GRC teams, CISOs, and anyone working with AI security.<br />
<br />
Use the coupon below to take the exam for free:<br />
Coupon: <span style="font-weight: bold;" class="mycode_b">AISECURITYFORALL</span><br />
<br />
You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view.<br />
<br />
<img src="https://media.licdn.com/dms/image/v2/D4D22AQHjUsPYjtWQCg/feedshare-image-high-res/B4DZ6A03J0JcAY-/0/1780277802254?e=1782345600&amp;v=beta&amp;t=a34p-7-h_c-K1UkajAawWmfsgNVC913YAm2D1a0UiNw" loading="lazy"  alt="[Image: 1780277802254?e=1782345600&amp;v=beta&amp;t=a34p...m2D1a0UiNw]" class="mycode_img" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-06-01]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-01</link>
			<pubDate>Tue, 02 Jun 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-06-01</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/nfgd330erfzkfvdi70dv3txlgpah/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3423013' style='color: #4aa3ff;' target='new'>page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/imnotr3al?type=user' style='color: #4aa3ff;' target='new'> <strong> Natthakul Raingoen</strong></a> was disclosed at June 2, 2026, 3:30 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An open redirect vulnerability was identified in page.line.me because redirect destinations were not properly restricted to trusted domains. This vulnerability could have been abused within an OAuth 2.0 authorization flow to cause the authorization response to be sent to an attacker-controlled endpoint, potentially exposing the authorization code issued after successful user authentication. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/nfgd330erfzkfvdi70dv3txlgpah/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3423013' style='color: #4aa3ff;' target='new'>page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/imnotr3al?type=user' style='color: #4aa3ff;' target='new'> <strong> Natthakul Raingoen</strong></a> was disclosed at June 2, 2026, 3:30 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An open redirect vulnerability was identified in page.line.me because redirect destinations were not properly restricted to trusted domains. This vulnerability could have been abused within an OAuth 2.0 authorization flow to cause the authorization response to be sent to an attacker-controlled endpoint, potentially exposing the authorization code issued after successful user authentication. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-05-30]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-05-30</link>
			<pubDate>Sun, 31 May 2026 07:00:05 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-05-30</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/variants/qv48zkf423avl8lwrpzkjsh87o74/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c?response-content-disposition=inline%3B%20filename%3D%22176697.png%22%3B%20filename%2A%3DUTF-8%27%27176697.png&response-content-type=image%2Fpng&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQGK6FURQ6LL3EJN7%2F20260531%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260531T070005Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjECYaCXVzLXdlc3QtMiJGMEQCIEMWJjCh6FW0FoQOLEKDST5HEaHtg4vQA4ktKq1RL0onAiANNlZa6PlfXaAmitfHMzbfvz3Dr7g7Zz0qaacBhlPwhCq7BQjv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAMaDDAxMzYxOTI3NDg0OSIMwJONlB5p1e6LAbrDKo8FDGqTstZ1OHRzq8yaH1bdKPxwz3YxOPtvXXaedrPXmIIzpUZEs7x8NAfP9T1d%2BVhZcIxGhWCQD5LOjjeiNdHNWYrdF7r9Suq2P3YtQxQh10tgDEy%2BaJYBOuB5zhDxxZLMHZm%2Br4vznsm7JFLY2wVOaoZ4H%2BtNYzFQc3tb6wrcqQYs8yHX2FjhJwtkGReMSw0BdD8PH5%2FwiFeD1uVSgds9kjL6Gez4QeLt8iAbl%2FofXzZ4q77z7CpazIpdr2Gqw0yGCbbS%2B5PNImVtdeNHSXyJDD0PkI9nu53VGZAbiDKKVD6JbJzOnoye1D1flLDMUckfGYkDATd7WszRw6FndCV1JMa0hNmUQDZKpnluqea6kPY4glbh1QflyZBPieWbDRR6S2U0bgNq4UcwmvHli9n7XMtC4nXiZUZp5yj6WuFW7Hmf6AHa1dDH2SWV5gf4FiVKWr5UIJ02%2FBq%2B%2BWM3zHXGSRBiWcf4YemIjW%2BelxpxbBAY3yRLWkKOYtiAi%2FKE7uR4TNcQvR4g6ykriFr8cm2kHu0u0kBu6FALDGps2jf5ZV%2BJEzp8YNO1qe90PtsRpElhXjtC2C64%2Fnpap91vrj41P%2FTjSPiPSXGGe8q5Q7neJDriCLDD7Jsd0dw9WmJdnMnj0Qr3kVCHRpc%2Btc5VRPf6sqU%2FcGfwiS%2F1KC7c%2FSNkW2Wq0F6Rh%2Fz3y0tI4IvftleWuFFahGqBekZKlIAz%2BtQapdMhP681bQi2EyQcTUQ%2F8M%2Bp31p6%2BvkpZE9%2BbcfjknM9bIoE%2BQV2foHcoe%2FTUunWyTw9JGMK1HeR0brZ7bne6dFxxA2K%2FyFn%2FHR%2FhJqvGVR1ZheQKX3KUEEQqSO6qe2i67e69A9dDCEs9nmJWN5pbDDbnu%2FQBjqyAduqeFW9uCOuURtgdlBFUjIGUKTJTiRAl8WzXUiKUhtRVtUa5fnml1vXs3p1FwvWq7Dy6VczGh7SKrPdoNCytdlWZzpJIQVVENFNLDcN0nWysfSdkIDidCSGEl3Cf7zlkiY8n0pd8WpcTsKb1gmbSLy3QJgF3BPfyMmltFCeub0vPPpKD7GzAv5B1WG1%2FoJHQiv3E0Qjo%2FF1sc9iKTiy3jGRPi1B2198uzq3aGZNOcSjg6w%3D&X-Amz-SignedHeaders=host&X-Amz-Signature=820b5b99cdd06114a342f042272fea8aa9b53be4e6bbb2b633910b1dfff05040' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3608558' style='color: #4aa3ff;' target='new'>Blind POST SSRF via Web Push Notification Endpoint</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/misop00p?type=user' style='color: #4aa3ff;' target='new'> <strong> Miso Poop</strong></a> was disclosed at May 30, 2026, 4:47 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in phpBB 4.0.0-alpha1 that allowed registered users to register arbitrary URLs as their Web Push notification endpoint. The endpoint URL was stored without validation and later used by the phpBB server to send outbound HTTP POST requests, potentially leading to blind POST server-side request forgery (SSRF) vulnerabilities. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/variants/qv48zkf423avl8lwrpzkjsh87o74/3f1ab5c6a9b6dadada1e6c8121700b884388bd0a43471fee1897a38ce57d0b2c?response-content-disposition=inline%3B%20filename%3D%22176697.png%22%3B%20filename%2A%3DUTF-8%27%27176697.png&response-content-type=image%2Fpng&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQGK6FURQ6LL3EJN7%2F20260531%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260531T070005Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjECYaCXVzLXdlc3QtMiJGMEQCIEMWJjCh6FW0FoQOLEKDST5HEaHtg4vQA4ktKq1RL0onAiANNlZa6PlfXaAmitfHMzbfvz3Dr7g7Zz0qaacBhlPwhCq7BQjv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAMaDDAxMzYxOTI3NDg0OSIMwJONlB5p1e6LAbrDKo8FDGqTstZ1OHRzq8yaH1bdKPxwz3YxOPtvXXaedrPXmIIzpUZEs7x8NAfP9T1d%2BVhZcIxGhWCQD5LOjjeiNdHNWYrdF7r9Suq2P3YtQxQh10tgDEy%2BaJYBOuB5zhDxxZLMHZm%2Br4vznsm7JFLY2wVOaoZ4H%2BtNYzFQc3tb6wrcqQYs8yHX2FjhJwtkGReMSw0BdD8PH5%2FwiFeD1uVSgds9kjL6Gez4QeLt8iAbl%2FofXzZ4q77z7CpazIpdr2Gqw0yGCbbS%2B5PNImVtdeNHSXyJDD0PkI9nu53VGZAbiDKKVD6JbJzOnoye1D1flLDMUckfGYkDATd7WszRw6FndCV1JMa0hNmUQDZKpnluqea6kPY4glbh1QflyZBPieWbDRR6S2U0bgNq4UcwmvHli9n7XMtC4nXiZUZp5yj6WuFW7Hmf6AHa1dDH2SWV5gf4FiVKWr5UIJ02%2FBq%2B%2BWM3zHXGSRBiWcf4YemIjW%2BelxpxbBAY3yRLWkKOYtiAi%2FKE7uR4TNcQvR4g6ykriFr8cm2kHu0u0kBu6FALDGps2jf5ZV%2BJEzp8YNO1qe90PtsRpElhXjtC2C64%2Fnpap91vrj41P%2FTjSPiPSXGGe8q5Q7neJDriCLDD7Jsd0dw9WmJdnMnj0Qr3kVCHRpc%2Btc5VRPf6sqU%2FcGfwiS%2F1KC7c%2FSNkW2Wq0F6Rh%2Fz3y0tI4IvftleWuFFahGqBekZKlIAz%2BtQapdMhP681bQi2EyQcTUQ%2F8M%2Bp31p6%2BvkpZE9%2BbcfjknM9bIoE%2BQV2foHcoe%2FTUunWyTw9JGMK1HeR0brZ7bne6dFxxA2K%2FyFn%2FHR%2FhJqvGVR1ZheQKX3KUEEQqSO6qe2i67e69A9dDCEs9nmJWN5pbDDbnu%2FQBjqyAduqeFW9uCOuURtgdlBFUjIGUKTJTiRAl8WzXUiKUhtRVtUa5fnml1vXs3p1FwvWq7Dy6VczGh7SKrPdoNCytdlWZzpJIQVVENFNLDcN0nWysfSdkIDidCSGEl3Cf7zlkiY8n0pd8WpcTsKb1gmbSLy3QJgF3BPfyMmltFCeub0vPPpKD7GzAv5B1WG1%2FoJHQiv3E0Qjo%2FF1sc9iKTiy3jGRPi1B2198uzq3aGZNOcSjg6w%3D&X-Amz-SignedHeaders=host&X-Amz-Signature=820b5b99cdd06114a342f042272fea8aa9b53be4e6bbb2b633910b1dfff05040' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3608558' style='color: #4aa3ff;' target='new'>Blind POST SSRF via Web Push Notification Endpoint</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/misop00p?type=user' style='color: #4aa3ff;' target='new'> <strong> Miso Poop</strong></a> was disclosed at May 30, 2026, 4:47 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in phpBB 4.0.0-alpha1 that allowed registered users to register arbitrary URLs as their Web Push notification endpoint. The endpoint URL was stored without validation and later used by the phpBB server to send outbound HTTP POST requests, potentially leading to blind POST server-side request forgery (SSRF) vulnerabilities. </p>
              </div><br>]]></content:encoded>
		</item>
	</channel>
</rss>