gratipay / inside.gratipay.com

Here lieth a pioneer in open source sustainability. RIP
https://gratipay.news/the-end-cbfba8f50981
57 stars 38 forks source link

/appendices/disclosures displays all reports including valid reports in the "Severity: None" section. #1185

Closed EdOverflow closed 6 years ago

EdOverflow commented 6 years ago

http://inside.gratipay.com/appendices/disclosures

The "Reflected XSS - gratipay.com" report (https://hackerone.com/reports/262852) was a severity medium issue.

image

The issue probably lies in: https://github.com/gratipay/inside.gratipay.com/blob/master/www/appendices/disclosures.spt