Google Docs link in JS files allows editing & reading survey information
Program: hackerone
Bug Type: Information disclosure
Bounty: 2500
Date: 2023-09-25
information-disclosure
data-leak
lack-of-permissions
Summary
The researcher who was monitoring Javascript files of hackerone found a new update that introduced a variable with a google docs link.
The google docs link was leaked via the file https://hackerone.com/assets/static/js/5930.078b8e86.chunk.js, The document was editable and had global read permission.