HackerOne Bug Bounty Disclosure: sql-injection-in-column-type-parameter-allows-arbitrary-sql-execution-suul - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-sql-injection-in-column-type-parameter-allows-arbitrary-sql-execution-suul/
I reported this and another vuln to MetaMask over #hackerone . It was the only communication platform available. Clearly, this needed a private report.
MetaMask marked this and another report as Not Applicable.
Curl accepted a report as Informative, which is great. Glad I reported a security bug properly. But, now I have a -5 HackerOne score and am locked out of coordinated vulnerability disclosure via H1.
I put users first by emailing curl a second vuln and breaking the HackerOne ToS.







