Hackerone impersonation

Disclosed: 2015-12-02 04:54:33 By abhisheksingh To security
Unknown
Vulnerability Details
You should restrict users to create user profile named "hacker0x01" because it represents 'hackerone' everywhere. Any user can create a profile named "hacker0x01" although he/she is a completely different user. This way user can potentially impersonate hackerone.
Actions
View on HackerOne
Report Stats
  • Report ID: 97377
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report