Loading HuntDB...

Khan Academy - HackerOne Reports

View on HackerOne
47
Total Reports
6
Critical
15
High
16
Medium
7
Low
Weakness: Improper Restriction of Authentication Attempts
Weakness: Unverified Password Change
Weakness: Uncontrolled Resource Consumption
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Unverified Password Change
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cleartext Storage of Sensitive Information
Medium
Weakness: Client-Side Enforcement of Server-Side Security
Weakness: Violation of Secure Design Principles
Weakness: Cross-site Scripting (XSS) - DOM
Critical
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Improper Access Control - Generic
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Improper Access Control - Generic

EMAIL SPOOFING

Reported by: hackthedevil | Disclosed:
Medium
Weakness: Privilege Escalation
Weakness: UI Redressing (Clickjacking)
Page 1 of 3 Next