Loading HuntDB...

Basecamp - HackerOne Reports

View on HackerOne
41
Total Reports
6
Critical
11
High
13
Medium
10
Low
Weakness: Information Disclosure
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Code Injection

HEY.com email stored XSS

Reported by: jouko | Disclosed:
Critical
Weakness: Cross-site Scripting (XSS) - Stored
Bounty: $5000.00
Weakness: Deserialization of Untrusted Data
Weakness: Improper Authentication - Generic
Weakness: HTTP Request Smuggling
Weakness: Improper Authentication - Generic
Bounty: $6337.00
Weakness: Cross-site Scripting (XSS) - DOM
Weakness: Deserialization of Untrusted Data

Login session not expire

Reported by: zukito | Disclosed:
Low
Weakness: Insufficient Session Expiration
Bounty: $100.00
Weakness: Phishing
Weakness: Business Logic Errors
Weakness: Improper Authentication - Generic
Bounty: $250.00
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Information Disclosure
Bounty: $8868.00
Weakness: Information Disclosure
Bounty: $100.00
Previous Page 2 of 3 Next