CYFARE.NET

CYFARE.NET

CyberSec & Tech Products

VULNERABILITY DISCLOSURE PROGRAM

Report vulnerabilities in cyfare.net and get recognized in our Hall of Fame!

Please report issues responsibly to: security@cyfare.net

Reflected XSS (Bypass) In Hyper Chat

Disclosed: 2025-06-07

Medium

An attacker was able to inject malformed characters in JSON to escape outside defined parameters and create custom JSON objects with custom data, resulting in Denial of Service across the site while rendering.

Reported By: Buvaneshvaran K.

Missing Secure Headers

Disclosed: 2025-01-31

Medium

Inadequate HSTS implementation, allowing potential unencrypted connections. Missing secure flag for sensitive HTTP cookies.

Reported By: Abdul Rauf Memon

Reflected XSS In Hyper Chat

Disclosed: 2024-12-04

Medium

An attacker was able to perform reflected cross site scripting by providing javascript in the chat window, causing the page to render the javascript in user context.

Reported By: Prithivik SL

DoS Via JSON Injection

Disclosed: 2024-11-03

High

An attacker was able to inject malformed characters in JSON to escape outside defined parameters and create custom JSON objects with custom data, resulting in Denial of Service across the site while rendering.

Reported By: 4nonimus