Linkedin Broken Link Hijacking on https://hemi.xyz/about

Disclosed: 2025-02-13 19:13:05 By an_gr_y To hemi_labs_vdp
Low
Vulnerability Details
## Summary: Hemi.xyz has an unclaimed broken linkedin link on their about page which can be claimed by any malicious user. And then later the malicious user can exploit this issue to deceive new visiter's. ## Steps To Reproduce: 1. Navigate to https://hemi.xyz/about 2. Click on the Gabriel Montes linkedin profile 3. You can see that it is takeovered ## Supporting Material/References: https://gist.github.com/EdOverflow/24e0bb929169eb948bb7f3d0a2d5528f. #1826892 ## POC {F4047848} ## Impact New users can be further deceived if they clicked on that hijacked link.
Actions
View on HackerOne
Report Stats
  • Report ID: 2990368
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report