Affirm - HackerOne Reports
View on HackerOne5
Total Reports
1
Critical
0
High
2
Medium
2
Low
Absence of Token expiry leads to Unauthorized login Access
Reported by:
yogesh_ojha
|
Disclosed:
Critical
Weakness: Improper Authentication - Generic
IDOR to view order information of users and personal information
Reported by:
xfiltrer
|
Disclosed:
Medium
Weakness: Insecure Direct Object Reference (IDOR)
Bounty: $500.00
Subdomain takeover of www█████████.affirm.com
Reported by:
ian
|
Disclosed:
Medium
Weakness: Business Logic Errors
Bounty: $500.00
Subdomain takeover due to non registered TLD [ ██████████.█████.██████.com ]
Reported by:
0xprial
|
Disclosed:
Low
Weakness: Improper Access Control - Generic