Impersonation via Broken Link Hijacking on https://sv.hellosign.com

Disclosed by
CoffeeAddict_exe
  • Program Dropbox
  • Disclosed date over 1 year ago
  • Reward $300
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Dropbox

This report demonstrates an unused social media account takeover. The unused social media account has been reclaimed.

Summary by CoffeeAddict_exe

Simple broken link hijacking bug in one of DropBox's websites were you could click on the twitter icon and be redirected to a malicious accout

Activity