Staff and Triage can modify the initial post of a report, including of already disclosed reports
Medium
Vulnerability Details
FULL DISCLOSURE: I am a HackerOne employee and learned about it through this submission: https://███████-/issues/67828
**Summary:**
Members of the HackerOne program (and likely other program members on their own program) and Triage can edit the information of the original report
I used https://hackerone.com/reports/2000000 to demonstrate and the changes have since been reverted.
**Description:**
### Steps To Reproduce
1. Go to any report, disclosed or undisclosed
2. Press "edit information" on the original post
3. Edit & save.
4. Your changes are saved
### Optional: Supporting Material/References (Screenshots)
{F2560190}
{F2560189} {F2560191}
{F2560195}
## Impact
Members and Triage can rewrite the story the hacker is trying to tell and edits are not transparant
- Give hackers a bad image in disclosed reports
- Tell a different story or lower impact artificially
- The body is supposed to be immutable after 20 minutes
Actions
View on HackerOneReport Stats
- Report ID: 2096271
- State: Closed
- Substate: resolved
- Upvotes: 42