Loading HuntDB...

Moneybird - HackerOne Reports

View on HackerOne
18
Total Reports
0
Critical
1
High
4
Medium
7
Low
Weakness: Violation of Secure Design Principles

Logging out any user

Reported by: japz | Disclosed:
Weakness: Violation of Secure Design Principles
Weakness: Insecure Direct Object Reference (IDOR)

XXE issue

Reported by: 4lemon | Disclosed:
Weakness: Command Injection - Generic

Stored XSS thru SVG upload

Reported by: 4lemon | Disclosed:
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cryptographic Issues - Generic
Weakness: Open Redirect
Weakness: Improper Access Control - Generic

Stored XSS at Moneybird

Reported by: hack_im | Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Uncontrolled Resource Consumption
Weakness: Improper Restriction of Authentication Attempts

No rate Limit

Reported by: mokhliss | Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Uncontrolled Resource Consumption
Weakness: Open Redirect

Stored XSS on add project

Reported by: tofla | Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Session Fixation