Discourse - HackerOne Reports
View on HackerOne17
Total Reports
1
Critical
12
High
2
Medium
2
Low
Any user with invite capabilities can take-over any account on Discourse
Reported by:
mishre
|
Disclosed:
Critical
Bounty: $1024.00
Web Cache Deception Attack (XSS)
Reported by:
bobrov
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
Bounty: $256.00
Account takeover at https://try.discourse.org due to no CSRF protection in connecting Yahoo account
Reported by:
avinash_
|
Disclosed:
High
Weakness: Cross-Site Request Forgery (CSRF)
XSS vulnerability on Audio and Video parsers
Reported by:
alberto__segura
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
Users can bookmark other user's messages
Reported by:
strukt
|
Disclosed:
Medium
Weakness: Privilege Escalation
XSS Vulnerability on Image link parser
Reported by:
alberto__segura
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
Any authenticated user can download full list of users, including email
Reported by:
arkadiyt
|
Disclosed:
Medium
Weakness: Privacy Violation
Bounty: $256.00
Gaining access to private topics using quoting feature
Reported by:
mishre
|
Disclosed:
High
Weakness: Improper Access Control - Generic
Bounty: $256.00
Stored XSS in posts because of absence of oembed variables values escaping
Reported by:
skavans
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
XSS in topics because of bandcamp preview engine vulnerability
Reported by:
skavans
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
Stored XSS in topics because of whitelisted_generic engine vulnerability
Reported by:
skavans
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
Stored XSS in "post last edited" option
Reported by:
luigigubello
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
Bounty: $256.00
CSRF-tokens on pages without no-cache headers, resulting in ATO when using CloudFlare proxy (Web Cache Deception)
Reported by:
fransrosen
|
Disclosed:
Low
Weakness: Cross-Site Request Forgery (CSRF)
Admin Command Injection via username in user_archive ExportCsvFile
Reported by:
ziot
|
Disclosed:
High
Weakness: Command Injection - Generic
Bounty: $512.00
Arbitrary Local-File Read from Admin - Restore From Backup due to Symlinks
Reported by:
ziot
|
Disclosed:
High
Weakness: Information Disclosure
Bounty: $512.00
DOM Based XSS in Discourse Search
Reported by:
khizer47
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
SSRF in upload IMG through URL
Reported by:
mariuszpoplawski
|
Disclosed:
Low
Weakness: Information Disclosure
Bounty: $64.00