Top Echelon Software - HackerOne Reports
View on HackerOne6
Total Reports
0
Critical
3
High
2
Medium
1
Low
Public and secret api key leaked in JavaScript source
Reported by:
lmhu
|
Disclosed:
High
Weakness: Improper Access Control - Generic
Clickjacking in main domain https://topechelon.com/
Reported by:
genz-1
|
Disclosed:
High
Wordpress Users Disclosure (/wp-json/wp/v2/users/)
Reported by:
hammodmt
|
Disclosed:
Medium
Weakness: Information Disclosure
xmlrpc.php FILE IS enable it will used for Bruteforce attack and Denial of Service(DoS)
Reported by:
mertergun305
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
able to login into login.topechelon.com
Reported by:
darkshadow1733
|
Disclosed:
High
Weakness: Privilege Escalation
Disable xmlrpc.php file
Reported by:
sohelahmed786
|
Disclosed:
Low