Loading HuntDB...

[Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content"

Low
H
HackerOne
Submitted None
Reported by japz

Vulnerability Details

Technical details and impact analysis

Hi Team, **Summary:** There is newly disclosed resolved report [Program Email Nofication settings ignored when being added as an external contributor](https://hackerone.com/reports/645264), However i found that the fix is incomplete. I have found that email invitation for a collaborator (bounty splitting) still disclosing the __Report title__ in email when the notification comes from `Manage Collaborator` invitation. ### Steps To Reproduce Assumes that __Manage Collaborator__ (bounty splitting) is enabled to the program 1. As a program admin, navigate to *Program Settings > Click Program >Click Email Notifications* 2. In email notification settings, select __No Content__ 3. Go to any report in your program and invite any hacker to the report to become a __Collaborator__. 4. Hacker can also invite __Collaborator__. 5. Check the invited hackers email, they will see the report title in the collaboration invitation email. ## PoC screenshot below: {F549793} {F549792} ## Impact Sensitive information disclosing bypassing the program settings. Regards Japz

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted