FormAssembly - HackerOne Reports
View on HackerOne6
Total Reports
0
Critical
2
High
2
Medium
2
Low
XSS in api_v1
Reported by:
ramsexy
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Generic
XSS on username when register to proffesional account
Reported by:
bogdantcaciuc
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Generic
scripts loader DOS vulnerability
Reported by:
badisman
|
Disclosed:
Medium
Weakness: Improper Restriction of Authentication Attempts
CVEs:
CVE-2018-6389
formassembly.com is vulnerable to padding-oracle attacks.
Reported by:
edoverflow
|
Disclosed:
Medium
Weakness: Cryptographic Issues - Generic
CVEs:
CVE-2016-2107
xmlrpc.php file is enable it will used for (DOS) and bruteforce attack
Reported by:
meepmerp
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
SSLv3 Poodle Vulnerability
Reported by:
pandaonair
|
Disclosed:
High
Weakness: Violation of Secure Design Principles