Staff and Triage can modify the initial post of a report, including of already disclosed reports
Medium
H
HackerOne
Submitted None
Team Summary
Official summary from HackerOne
Update: We've been notified of reports that describe a similar vulnerability, this is a duplicate of #2061367 - the hacker has been awarded with the bounty they deserved.
Actions:
Reported by
zerotea
Vulnerability Details
Technical details and impact analysis
FULL DISCLOSURE: I am a HackerOne employee and learned about it through this submission: https://███████-/issues/67828
**Summary:**
Members of the HackerOne program (and likely other program members on their own program) and Triage can edit the information of the original report
I used https://hackerone.com/reports/2000000 to demonstrate and the changes have since been reverted.
**Description:**
### Steps To Reproduce
1. Go to any report, disclosed or undisclosed
2. Press "edit information" on the original post
3. Edit & save.
4. Your changes are saved
### Optional: Supporting Material/References (Screenshots)
{F2560190}
{F2560189} {F2560191}
{F2560195}
## Impact
Members and Triage can rewrite the story the hacker is trying to tell and edits are not transparant
- Give hackers a bad image in disclosed reports
- Tell a different story or lower impact artificially
- The body is supposed to be immutable after 20 minutes
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic