Nord Security - HackerOne Reports
View on HackerOne47
Total Reports
2
Critical
3
High
18
Medium
14
Low
Denial of Service with Cookie Bomb
Reported by:
bihari_web
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Cross Origin Resource Sharing Misconfiguration | Lead to sensitive information
Reported by:
hridoy-ahmed
|
Disclosed:
Medium
Weakness: Improper Access Control - Generic
IDOR allow access to payments data of any user
Reported by:
dakitu
|
Disclosed:
High
Weakness: Insecure Direct Object Reference (IDOR)
Version problem in wordpress leads to the many vulnearability
Reported by:
bobby6102000
|
Disclosed:
Low
No Rate Limit On Forgot Password Page Of NordVPN
Reported by:
th3pr0xyb0y
|
Disclosed:
Medium
Weakness: Improper Authentication - Generic
Password Reset Link Leaked In Refer Header In Request To Third Party Sites
Reported by:
th3pr0xyb0y
|
Disclosed:
Low
Weakness: Cleartext Transmission of Sensitive Information
Arbitrary Set-Cookie via "?coupon=" due to semi-colon not encoded
Reported by:
yuyudhn
|
Disclosed:
Low
Weakness: Violation of Secure Design Principles
Html Injection and Possible XSS in main nordvpn.com domain
Reported by:
kiriknik
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Misconfigured web directory allows to retrieve public proxy list
Reported by:
zhh
|
Disclosed:
Weakness: Information Disclosure
UI Redressing (Clickjacking) vulnerability
Reported by:
be327e0cff8893bf8ab8592
|
Disclosed:
Medium
Weakness: UI Redressing (Clickjacking)
Getting SmartDNS for free from - join.nordvpn.com
Reported by:
salahhasoneh
|
Disclosed:
High
Weakness: Improper Authentication - Generic
Open redirect
Reported by:
nickelheck
|
Disclosed:
Medium
Weakness: Open Redirect
Disclosure of User Information
Reported by:
shardulb_23
|
Disclosed:
Low
Weakness: Information Disclosure
Potential leak of server side software at repogohi.nordvpn.com
Reported by:
zerody
|
Disclosed:
Medium
Weakness: Improper Access Control - Generic
Blind SSRF on debug.nordvpn.com due to misconfigured sentry instance
Reported by:
mase289
|
Disclosed:
Low
Weakness: Server-Side Request Forgery (SSRF)
User data not anonymized is sent to analytics server
Reported by:
martinbydefault
|
Disclosed:
Medium
Weakness: Privacy Violation
xmlrpc.php FILE IS enable it will used for Bruteforce attack and Denial of Service(DoS)
Reported by:
shardulb_23
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
Connection informaton is sent to a third-party service
Reported by:
martinbydefault
|
Disclosed:
Critical
Weakness: Privacy Violation
DoS of https://nordvpn.com/ via CVE-2018-6389 exploitation
Reported by:
cassiomcampos
|
Disclosed:
Low
CVEs:
CVE-2018-6389
Email verification bypass for manual connection setup using service credentials
Reported by:
yozzo_
|
Disclosed:
Medium
Page 1 of 3
Next