Researcher gets email updates on a private program after he/she quits that program.

Disclosed: 2016-11-21 08:12:53 By sasi2103 To security
Low
Vulnerability Details
**Summary:** I found out that after I quit private program, I still gets update about that program, e.g. new scope changes/amount of money and etc. **Description (Include Impact):** I noticed that if I quit program I still gets email updates about the private program, private data can be leak on that email. ### Steps To Reproduce 1. I got invite to █████ private program. 2. After period of time I quit that program. 3. I still get email updates about that program. ### soultions 1. Remove email address from program once hacker quit. 2. Set boolean flag, true/false once the user quit. (The flag can help once the user gets invite again or if he/she wants to rejoin). Thanks, Sasi
Actions
View on HackerOne
Report Stats
  • Report ID: 174449
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report