Urban Company - HackerOne Reports
View on HackerOne6
Total Reports
1
Critical
0
High
2
Medium
2
Low
Broken Link on Urban Company's Vulnerability Submission Form
Reported by:
thruster
|
Disclosed:
Low
Weakness: Violation of Secure Design Principles
Exposed data of credit card details to hacker or attacker.
Reported by:
nispat
|
Disclosed:
Medium
Weakness: Privacy Violation
Critical full compromise of jarvis-new.urbanclap.com via weak session signing
Reported by:
ian
|
Disclosed:
Critical
Weakness: Improper Authentication - Generic
Bounty: $1500.00
Insufficient Session Expiration
Reported by:
vibhushan
|
Disclosed:
Low
Weakness: Insufficient Session Expiration
Host header injection that bypassed protection and allowed accessing multiple subdomains
Reported by:
musashi42
|
Disclosed:
Medium
Weakness: Server-Side Request Forgery (SSRF)
Bounty: $500.00
Private ip leaking through response
Reported by:
t3chn0phil3
|
Disclosed:
Weakness: Information Disclosure