Hacker News new | ask | show | jobs
by mikesea 3441 days ago
Someone reported this same vulnerability to us via HackerOne months ago. We worked with Sendgrid support to re-claim the domain and they said they were urgently working to fix the issue, or not.

Edit: just saw this post was from September. Author probably made thousands in rewards circulating this vulnerability.

1 comments

I do not believe the author circulated this report to multiple companies, however once it was made public a number of other reporters in the community did and continued to iterate on it until SendGrid fixed the issues.

Source: I am a member of said community: https://bugcrowd.com/bored-engineer, https://hackerone.com/bored-engineer, etc