Month: August 2024

HackerOne Bug Bounty Disclosure: course-registration-form-allowing-an-attacker-to-dump-all-the-candidate-name-who-had-enrolled-for-the-course-steveflex

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:steveflexLink to Submitters Profile:https://hackerone.com/steveflex Report Title:Course Registration Form Allowing...

HackerOne Bug Bounty Disclosure: dod-workstation-exposed-to-internet-via-tinypilot-kvm-with-no-authentication-socpuppet

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:socpuppetLink to Submitters Profile:https://hackerone.com/socpuppet Report Title:DoD workstation exposed to...