Some limited confidential information can still be accessed after a user exits a private program

Disclosed: 2024-01-19 13:11:44 By mega7- To security
Medium
Vulnerability Details
Good morning team!!! I identified a bug where it is possible to access some limited confidential information from a private program even after you have already exited that program. information like: :number of domains :Bounties paid :Number of hackers paid :Response efficiency :Minimum reward and maximum reward :Sobre steps: 1:do you accept a private invitation 2:you add this program to your favorites 3:the expiry date for sending reports arrives 4:Now you can no longer send reports to this program or have access to its policy page 5:now go to opportunities -> My programs 6:And there is your program and you have access to the information mentioned above ## Impact Disclosure of private program information
Actions
View on HackerOne
Report Stats
  • Report ID: 2278865
  • State: Closed
  • Substate: resolved
  • Upvotes: 77
Share this report