Program Member Could Duplicate Report To A Non Related Program Original Report

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

Program Member Could Duplicate Report To A Non Related Program Original Report

Post by Shane1145 »

A researcher found a vulnerability on setting duplicate report as program owner. He was able to duplicate a report to a report that doesn't have relation with the program. For example we can duplicate to a public report in hacktivity.



https://hackerone.com/reports/2513082
Post Reply