Alohi - HackerOne Reports
View on HackerOne4
Total Reports
0
Critical
0
High
1
Medium
3
Low
Waitlist bypass for accessing SIGN.PLUS Beta
Reported by:
darkknight4688
|
Disclosed:
Low
Weakness: Improper Access Control - Generic
Misconfigured rate limit for SMS phone verification endpoint
Reported by:
shamim_12__
|
Disclosed:
Medium
Weakness: Business Logic Errors
Weak rate limit for SIGN.PLUS email verification
Reported by:
zeesozee
|
Disclosed:
Low
Misconfigured rate limit at app.sign.plus/forgot_password
Reported by:
shamim_12__
|
Disclosed:
Low
Weakness: Business Logic Errors