Some limited confidential information can still be accessed after a user exits a private program
Medium
H
HackerOne
Submitted None
Actions:
Reported by
ahacker1-
Vulnerability Details
Technical details and impact analysis
Good morning team!!!
I identified a bug where it is possible to access some limited confidential information from a private program even after you have already exited that program.
information like:
:number of domains
:Bounties paid
:Number of hackers paid
:Response efficiency
:Minimum reward and maximum reward
:Sobre
steps:
1:do you accept a private invitation
2:you add this program to your favorites
3:the expiry date for sending reports arrives
4:Now you can no longer send reports to this program or have access to its policy page
5:now go to opportunities -> My programs
6:And there is your program and you have access to the information mentioned above
## Impact
Disclosure of private program information
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$50.00
Submitted
Weakness
Information Disclosure