Program Member Could Duplicate Report To A Non Related Program Original Report
Posted: Mon Jan 13, 2025 4:29 am
A researcher found a vulnerability on setting duplicate report as program owner. He was able to duplicate a report to a report that doesn't have relation with the program. For example we can duplicate to a public report in hacktivity.
https://hackerone.com/reports/2513082
https://hackerone.com/reports/2513082