Courier Program Statistics


View program

13 total issues disclosed

$0 total paid publicly

Most disclosed (2 disclosures) — Insufficient Session Expiration



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Missing SPF record on trycourier.app Misconfiguration musab_alharany Low 2022-02-17
Broken Authentication Session Token Bug Insufficient Session Expiration palakmahipal Medium 2022-02-16
Session Fixiation allow attacker to create new evil workspace without being logged in [ Insecure Session management ] Session Fixation basant0x01 Medium 2021-09-16
[3] Bypassing IP Based Rate Limit Blocking leads to rate limit bypass in Courier Login Panel Uncontrolled Resource Consumption basant0x01 None 2021-09-16
Possible to invite any team member without being logged in. [ Session Management Issue ] Insufficient Session Expiration basant0x01 Medium 2021-09-03
2 Bypass of #1067533 rate limit via X-Forwarded-For<space>: Source IP on ( www.trycourier.app ) Uncontrolled Resource Consumption basant0x01 Medium 2021-08-27
[OPEN S3 BUCKET] All uploaded files are public. Misconfiguration n0x496n Medium 2021-04-01
Rate limit function bypass can leads to occur huge critical problem into website. Improper Access Control - Generic basant0x01 Medium 2021-01-08
Bypass Too Many Requests Sign Up Authentication Bypass Using an Alternate Path or Channel 34n3kjb4j3b4jh Medium 2020-07-30
Missing rate limit in signup Form Improper Authentication - Generic ahmedelmalky Medium 2020-07-29
SSO Provider Credential Cache (logged out of Google/GitHub, could still log into Courier) None supplied t3chn0phil3 Low 2020-07-20
Logout page does not prevent CSRF Cross-Site Request Forgery (CSRF) hackerboy404 Low 2020-07-06
disable test send feature if user's email address isn't verified Denial of Service vaalici High 2020-06-30