Triager/Team members can edit hacker's report and hacker is not even notified

Disclosed: 2023-08-31 09:28:28 By kalkii To security
Medium
Vulnerability Details
**Summary:** Hi Team I have created a dummy program and I noticed that Triager/Team member can edit hacker's report. **If you say this is a feature for the team, there should be a mechanism to ask permission from hacker to edit the report ** ### Steps To Reproduce 1. Create a dummy report 2. Open the report as team member 3. You will see a edit option near hacker's report 4. Using that option edit the report █████ ## Impact A triager/team member may edit hacker's report which highly impact the integrity of the report as there is no way hacker can proof that whether his submitted report was edited or not as you can see I have changed the whole content of the report and it also not notifying that the report has been updated
Actions
View on HackerOne
Report Stats
  • Report ID: 2061367
  • State: Closed
  • Substate: resolved
  • Upvotes: 78
Share this report