Staff and Triage can modify the initial post of a report, including of already disclosed reports

Disclosed: 2023-08-28 11:33:37 By zerotea To security
Medium
Vulnerability Details
FULL DISCLOSURE: I am a HackerOne employee and learned about it through this submission: https://███████-/issues/67828 **Summary:** Members of the HackerOne program (and likely other program members on their own program) and Triage can edit the information of the original report I used https://hackerone.com/reports/2000000 to demonstrate and the changes have since been reverted. **Description:** ### Steps To Reproduce 1. Go to any report, disclosed or undisclosed 2. Press "edit information" on the original post 3. Edit & save. 4. Your changes are saved ### Optional: Supporting Material/References (Screenshots) {F2560190} {F2560189} {F2560191} {F2560195} ## Impact Members and Triage can rewrite the story the hacker is trying to tell and edits are not transparant - Give hackers a bad image in disclosed reports - Tell a different story or lower impact artificially - The body is supposed to be immutable after 20 minutes
Actions
View on HackerOne
Report Stats
  • Report ID: 2096271
  • State: Closed
  • Substate: resolved
  • Upvotes: 42
Share this report