We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
It is possible to read DMs and follower-only posts sent by a hollo user without authorization.
This leaks DMs.
Example: As seen on phanpy: As seen on webfinger browser:
Summary
It is possible to read DMs and follower-only posts sent by a hollo user without authorization.
Details
PoC
Impact
This leaks DMs.
Example:


As seen on phanpy:
As seen on webfinger browser: