Information disclosure via policy update notifications after removal from program

Disclosed: 2016-10-29 01:29:57 By staytuned To security
Low
Vulnerability Details
**Summary:** information disclosure after removed from any program **Description (Include Impact):** after subscribing to changes for any program ( Notify me of changes ) then when the program removed you , you could still recieve the changes notification ### Steps To Reproduce 1. i have subscribed for Mindoktor ( Notify me of changes ) 2. yesterday Mindoktor went from public to private 3. even though i was not there in program , i have received the notification of their policy changes Hope you would fix this Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 177484
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report