Internal attachments can be exported via "Export as .zip" feature

Disclosed: 2016-11-30 09:18:19 By japz To security
High
Vulnerability Details
Hello HackerOne Team This newly disclosed report: #182358 __Partial disclosure of report activity through new "Export as .zip" feature__ was not completely fix. I have found that i can still view the attachment after it is being removed on the thread. Best PoC is this #182358 since this is the newly fix and disclosed. Steps to reproduce 1. Go to https://hackerone.com/reports/182358 2. Export the report as .zip 3. Now extract the .zip file (`HackerOne_Report-security#182358.zip`) 4. You will see that the image is still there, but base on the thread, you guys removed it on disclosed report. I have attached the .zip file downloaded and save on my local and i can still view the removed image. __Disclosed partially removed attachment:__ {F138022} Regards Japz
Actions
View on HackerOne
Report Stats
  • Report ID: 186230
  • State: Closed
  • Substate: resolved
  • Upvotes: 257
Share this report