HackerOne Bug Bounty Disclosure: conduit-feed-publish-api-allows-you-to-spoof-other-users-or-make-it-look-like-you-have-access-to-a-restricted-objectbydyls
Programme
HackerOne
- Phabricator
Submitted by
- dyls
Report
Conduit feed.publish API allows you to spoof other users or make it look like you have access to a restricted object