Some limited confidential information can still be accessed after a user exits a private program
Medium
Vulnerability Details
Good morning team!!!
I identified a bug where it is possible to access some limited confidential information from a private program even after you have already exited that program.
information like:
:number of domains
:Bounties paid
:Number of hackers paid
:Response efficiency
:Minimum reward and maximum reward
:Sobre
steps:
1:do you accept a private invitation
2:you add this program to your favorites
3:the expiry date for sending reports arrives
4:Now you can no longer send reports to this program or have access to its policy page
5:now go to opportunities -> My programs
6:And there is your program and you have access to the information mentioned above
## Impact
Disclosure of private program information
Actions
View on HackerOneReport Stats
- Report ID: 2278865
- State: Closed
- Substate: resolved
- Upvotes: 77