WHO COVID-19 Mobile App Program Statistics
7 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Improper Input Validation
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| ArcGIS Rest Service linked to unsecured survey data | Authentication Bypass Using an Alternate Path or Channel | y1ngxi0ng | Medium | 2021-02-13 |
| Error Page Text Injection (no compromise) | Misconfiguration | theendisnear | None | 2021-02-13 |
| Improper Input Validation on User's Location on PUT /WhoService/putLocation Could Affect Availability/Falsify Users | Improper Input Validation | humayunalikhan | Medium | 2021-01-12 |
| Internal API endpoint is accesible for everyone | Improper Access Control - Generic | arnonymous | Medium | 2020-12-28 |
| DMARC and SPF records | None supplied | hackz-bhavin | Medium | 2020-12-22 |
| Improper Input Validation on User's Location on PUT /WhoService/putLocation Could Affect Availability/Falsify Users | Improper Input Validation | spaceraccoon | Low | 2020-12-22 |
| Probably unexploitable XSS via Header Injection | Cross-site Scripting (XSS) - Reflected | d0nut | Low | 2020-12-21 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles