Global Hacktivity

Public, curated security activity across the platform.

Public Curated
CSRF at Self-close report function
2025-12-29 17:38 Hackrate Responsible Disclosure Program 5cb67624-6648-4c87-81f2-691130f95bd7
@Labda

It's important to note, that the lack of CSRF protection is generally out of scope, but I reported it, because this request is just a simple GET method. An attacker is able to craft an URL, what contains the ID of a report, and if the user, who has access to the report, clicks on it, the report is being self closed.

Low Details available Resolved
Cloudflare Transform via URL Injection (Potential SSRF Vulnerability)
2025-12-29 17:38 Hackrate Responsible Disclosure Program ad5e8ea0-78b1-4b6c-a3be-9132a7308e33
@MRKNIGHTNIDU

A potential Server-Side Request Forgery (SSRF) vulnerability was identified in the Cloudflare image transformation feature via URL injection on the domain https://www.hckrt.com. The service allows arbitrary URLs to be processed through the /cdn-cgi/image/ endpoint, which may permit unauthorized internal or external requests.

Medium Details available Resolved
About this feed

Global Hacktivity highlights selected security events published by the platform.

  • Public by default
  • Curated content only
  • No sensitive details exposed
Submission policy
Only platform administrators can publish items to this global feed. Events are reviewed before becoming public.
Hackrate

Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.

US Patent Applied for HackGATE #63/645,845

Checking service status...

Capterra G2 Rating

Hackrate Ethical Hacking Platform |
2025 ©