Private leaderboard owner email disclosure when sending invites

Disclosed: 2020-08-28 23:15:01 By nrekany To wakatime
Unknown
Vulnerability Details
Hi , the `unVerify email` disclosure when invite to any one on Leaderboards . Step .. 1- create account [email protected] . 2- not verify email . 3- go to Leaderboards . 4- check invite any email [email protected] . your friends. 5- your friends look inbox the waketime invite it say > [email protected] wants to add you to the private leaderboard test"h1h/h1 How To Fix ? > in your friends inbox must be say [Full Name/username] wants to add you to the private leaderboard test"h1h/h1 ## Impact Disclosure email and unverify
Actions
View on HackerOne
Report Stats
  • Report ID: 969988
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report