Loading HuntDB...

Starbucks - HackerOne Reports

View on HackerOne
128
Total Reports
20
Critical
39
High
41
Medium
21
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Improper Access Control - Generic
Weakness: Uncontrolled Resource Consumption

PHPinfo page

Reported by: linkks | Disclosed:
Low
Weakness: Information Disclosure
Weakness: SQL Injection

csrf blogs.starbucks.com

Reported by: w2w | Disclosed:
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Improper Access Control - Generic
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Improper Access Control - Generic
Weakness: Unverified Password Change
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Improper Authentication - Generic
Weakness: Path Traversal
Weakness: Open Redirect
Page 1 of 7 Next