Security Hall of Fame
We would like to thank the following individuals and/or organizations, who have responsibly disclosed vulnerabilities to us.
09 Jun 2023 |
Reported access control issues on a Hipex backup server |
|
25 May 2023 |
Reported a privilege escalation issue on Hypernode |
|
03 Jan 2023 |
Reported access control issues in our git repository |
|
16 Apr 2022 |
Reported possible information leakage from a legacy service. |
|
13 Jan 2022 |
Reported a Reflective XSS attack on marketing sites. |
|
31 May 2021 |
Reported a Reflective XSS attack on marketing sites. |
|
31 May 2021 |
Reported information leakage from an internal server. |
|
9 September 2020 |
Reported a password reset token leak |
|
1 August 2020 |
Reported an account takeover using IDN homograph attack. |
|
1 July 2020 |
Reported a flaw in our password reset flow |
|
14 May 2020 |
Reported information leakage from marketing sites. |
|
28 September 2019 |
Reported a Cross site scripting (XSS) on magereport.com. |
|
21 March 2019 |
Reported a misconfiguration that allowed user impersonation on Hypernode hosted webshops. |
|
12 March 2019 |
Reported information leakage from an internal deployment server. |
|
28 August 2018 |
Reported a privilege escalation on Hypernode, leading to a local root exploit. |
|
1 June 2018 |
Reported a misconfiguration that allowed a Hypernode’s preconfigured security settings to be bypassed. |