Hacker can request mediation for published reports

Disclosed: 2018-11-27 17:31:27 By haxta4ok00 To security
Low
Vulnerability Details
Hi team, @jobert **Summary:** After creating the publish report, we do not have a field to send the requested meditation from HackerOne Support **Description:** ### Steps To Reproduce 1. Create publish report for any program ████████ 2. Use query `https://hackerone.com/reports/`***number_publish_report***`/hacker_help` My `https://hackerone.com/reports/███/hacker_help` POST: `message=123&mediation_type=unresponsive` 3. Next check report ███ I understand the degree of low, but this is a disagreement between the web and the end point. Sorry i bad speak english I hope you understand me Thank you,haxta4ok00 ## Impact Creating a query `requested meditation from HackerOne Support` without being able to do so
Actions
View on HackerOne
Report Stats
  • Report ID: 412988
  • State: Closed
  • Substate: resolved
  • Upvotes: 20
Share this report