Loading HuntDB...

Program metrics disclosed response_efficiency_percentage via /program_name json response despite the team decided not to show on their profile

Medium
H
HackerOne
Submitted None
Reported by japz

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hi Team, **Summary:** First of all, i am not sure if a private program or any program have the capability to not show their response efficiency, __but i assume they have because i saw some private programs that do not show response efficiency percentage on their public page__. **Description:** Below list of private program was not showing their `response efficiency percentage` on their public profile, but using `profile_metrics.json` response, the percentage can be view resulting an information disclosure about the program. █████████ = 100% ███████ = 100% ████ = 66% ████ = 68% ██████ = 52% ### Steps To Reproduce 1. Go to ██████████ 2. Observed that response efficiency was not visible 3. Now go to █████████/profile_metrics.json 4. I can confirm that `66%` is the percentage of ██████████ because of this `"response_efficiency_percentage":66` ## PoC screenshot below: ███████ ## Impact Information disclosure despite the private program is not showing the response efficiency percentage.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2500.00

Submitted

Weakness

Information Disclosure