Loading HuntDB...

Staff and Triage can modify the initial post of a report, including of already disclosed reports

Medium
H
HackerOne
Submitted None

Team Summary

Official summary from HackerOne

Update: We've been notified of reports that describe a similar vulnerability, this is a duplicate of #2061367 - the hacker has been awarded with the bounty they deserved.

Reported by zerotea

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
FULL DISCLOSURE: I am a HackerOne employee and learned about it through this submission: https://███████-/issues/67828 **Summary:** Members of the HackerOne program (and likely other program members on their own program) and Triage can edit the information of the original report I used https://hackerone.com/reports/2000000 to demonstrate and the changes have since been reverted. **Description:** ### Steps To Reproduce 1. Go to any report, disclosed or undisclosed 2. Press "edit information" on the original post 3. Edit & save. 4. Your changes are saved ### Optional: Supporting Material/References (Screenshots) {F2560190} {F2560189} {F2560191} {F2560195} ## Impact Members and Triage can rewrite the story the hacker is trying to tell and edits are not transparant - Give hackers a bad image in disclosed reports - Tell a different story or lower impact artificially - The body is supposed to be immutable after 20 minutes

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic