Disclosing a private program in an external link if program is paused
Low
Vulnerability Details
**Summary:**
Hi team
**Description:**
If the program is paused that we will not be able to send reports to this program and if we try to directly contact the link https://hackerone.com/external_programm_paused/reports/new we will be returned to the main page https://hackerone.com/external_programm_paused
### Steps To Reproduce
1. PoC ██████████ , ███████
2.
███████
█████
3. After i will be redirect in main page ████████ and ███████████
Result : ████████, █████████ - private program and status - paused
As it seems to me here insufficient check of authorization of me to these programs at this point
I tested on the second account where there is no program.
Sorry i bad speak english
I hope you understand me
Thank you,haxta4ok00
## Impact
Disclosing a private program in an external link if program is paused
Actions
View on HackerOneReport Stats
- Report ID: 418474
- State: Closed
- Substate: resolved
- Upvotes: 44