WakaTime - HackerOne Reports
View on HackerOne64
Total Reports
0
Critical
3
High
9
Medium
24
Low
Forgot password link doesn't expire after used, only after some hours
Reported by:
mohammad_obaid
|
Disclosed:
Low
Weakness: Weak Password Recovery Mechanism for Forgotten Password
[Privilege Escalation] Authenticated users can manipulate others fullname without their knowledge
Reported by:
r3y
|
Disclosed:
Medium
Weakness: Privilege Escalation
Login page password - guessing attack
Reported by:
paxtammy
|
Disclosed:
Low
Weakness: Improper Restriction of Authentication Attempts
previous token seems to work even though it does not verify email
Reported by:
rashedhasan007
|
Disclosed:
Low
Weakness: Violation of Secure Design Principles
Previous
Page 4 of 4