[Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content"
Low
H
HackerOne
Submitted None
Actions:
Reported by
japz
Vulnerability Details
Technical details and impact analysis
Hi Team,
**Summary:**
There is newly disclosed resolved report [Program Email Nofication settings ignored when being added as an external contributor](https://hackerone.com/reports/645264), However i found that the fix is incomplete.
I have found that email invitation for a collaborator (bounty splitting) still disclosing the __Report title__ in email when the notification comes from `Manage Collaborator` invitation.
### Steps To Reproduce
Assumes that __Manage Collaborator__ (bounty splitting) is enabled to the program
1. As a program admin, navigate to *Program Settings > Click Program >Click Email Notifications*
2. In email notification settings, select __No Content__
3. Go to any report in your program and invite any hacker to the report to become a __Collaborator__.
4. Hacker can also invite __Collaborator__.
5. Check the invited hackers email, they will see the report title in the collaboration invitation email.
## PoC screenshot below:
{F549793}
{F549792}
## Impact
Sensitive information disclosing bypassing the program settings.
Regards
Japz
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00