Private leaderboard owner email disclosure when sending invites
Unknown
Vulnerability Details
Hi ,
the `unVerify email` disclosure when invite to any one on Leaderboards .
Step ..
1- create account [email protected] .
2- not verify email .
3- go to Leaderboards .
4- check invite any email [email protected] . your friends.
5- your friends look inbox the waketime invite it say
> [email protected] wants to add you to the private leaderboard test"h1h/h1
How To Fix ?
> in your friends inbox must be say [Full Name/username] wants to add you to the private leaderboard test"h1h/h1
## Impact
Disclosure email and unverify
Actions
View on HackerOneReport Stats
- Report ID: 969988
- State: Closed
- Substate: resolved
- Upvotes: 6