Private program disclosure through notifications
Low
Vulnerability Details
Hello Team,
**Summary:**
I recently came across hackerone report: https://hackerone.com/reports/1179241 . I though this was fixed but today I have have faced similar experience. I have received a Scope and policy update from the program "██████" which I am not part of.
████████
When I was clicking on the notifications, scope update notification is taking me to hacktivity page and policy update notification is taking me to "Page not found page", I think the previous fix to #1179241 is not complete . As a proof, I have attached a video poc and screenshots.
### Steps To Reproduce
1. Login to Hackerone account
2. Checked my notifications
## POC
██████████
## Impact
I was able to received notification updates of a private program to which I am not part of. This discloses the private program handle to which i am not part of.
Actions
View on HackerOneReport Stats
- Report ID: 1234746
- State: Closed
- Substate: resolved
- Upvotes: 36