Bug Bounty

HackerOne Bug Bounty Disclosure: local-file-disclosure-on-the-hxxps-edu-leads-to-the-full-source-code-disclosure-and-credentials-leak-sp-d-rs

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:sp1d3rsLink to Submitters Profile:https://hackerone.com/sp1d3rs Report Title:Local File Disclosure on...

HackerOne Bug Bounty Disclosure: monitoring-prow-canary-k-s-io-is-vulnerable-to-cve-grafana-day-jub-bs

Company Name: Kubernetes Company HackerOne URL: https://hackerone.com/kubernetes Submitted By:jub0bsLink to Submitters Profile:https://hackerone.com/jub0bs Report Title:monitoringprow-canaryk8sio is vulnerable to CVE-2022-21703 (Grafana 0-day)Report...

HackerOne Bug Bounty Disclosure: subdomain-takeover-of-ci-support-booking-com-pointing-to-zendesk-jub-bs

Company Name: Booking.com Company HackerOne URL: https://hackerone.com/bookingcom Submitted By:jub0bsLink to Submitters Profile:https://hackerone.com/jub0bs Report Title:Subdomain takeover of ci-supportbookingcom (pointing to Zendesk)Report...

HackerOne Bug Bounty Disclosure: cloudflare-cdn-cgi-path-allows-resizing-images-from-unauthorised-sources-on-enjinusercontent-com–whoami

Company Name: Enjin Company HackerOne URL: https://hackerone.com/enjin Submitted By:19whoami19Link to Submitters Profile:https://hackerone.com/19whoami19 Report Title:Cloudflare /cdn-cgi/ path allows resizing images from...

HackerOne Bug Bounty Disclosure: -meetup-world-id-oidc-insufficient-filtering-of-state-parameter-in-response-mode-form-post-leads-to-xss-and-ato-lauritz

Company Name: Tools for Humanity Company HackerOne URL: https://hackerone.com/toolsforhumanity Submitted By:lauritzLink to Submitters Profile:https://hackerone.com/lauritz Report Title: Insufficient Filtering of "state"...

HackerOne Bug Bounty Disclosure: -package-name-can-be-set-as-desired-when-submitting-a-pentest-opportunity-form-iam-srpk

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:iam_srpkLink to Submitters Profile:https://hackerone.com/iam_srpk Report Title:"package_name" can be set as desired when...

HackerOne Bug Bounty Disclosure: access-control-vulnerability-enabling-unauthorized-access-to-limited-disclosure-reports-akashhamal-x

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:akashhamal0x01Link to Submitters Profile:https://hackerone.com/akashhamal0x01 Report Title:Access Control Vulnerability Enabling Unauthorized Access to...

HackerOne Bug Bounty Disclosure: account-deletion-using-the-v-account-destroy-api-endpoint-using-account-password-without-fa-verification-erdy

Company Name: Mozilla Company HackerOne URL: https://hackerone.com/mozilla Submitted By:erdyLink to Submitters Profile:https://hackerone.com/erdy Report Title:Account deletion using the /v1/account/destroy API endpoint...

HackerOne Bug Bounty Disclosure: -spot-check-ability-to-disclose-metadata-about-spot-checks-number-of-hackers-hackers-criteria-via-spotchecksinglequery-nagli

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:nagliLink to Submitters Profile:https://hackerone.com/nagli Report Title: - Ability to disclose metadata about...

HackerOne Bug Bounty Disclosure: inadequate-redaction-exposes-sensitive-information-via-the-sharereportviaemail-graphql-endpoint-iambouali

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:iamboualiLink to Submitters Profile:https://hackerone.com/iambouali Report Title:Inadequate redaction exposes sensitive information via the...

HackerOne Bug Bounty Disclosure: changing-the-administrator-password-via-admin-console-does-not-invalidate-other-sessions-osama-hamad

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:osama-hamadLink to Submitters Profile:https://hackerone.com/osama-hamad Report Title:Changing the administrator password via...

HackerOne Bug Bounty Disclosure: a-user-with-only-modify-settings-permmision-could-takeover-any-user-accounts-osama-hamad

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:osama-hamadLink to Submitters Profile:https://hackerone.com/osama-hamad Report Title:A user with only permmision...

HackerOne Bug Bounty Disclosure: any-user-could-upload-attachments-to-pentest-scoping-form-they-don-t-have-access-to-hillybot

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:hillybot__Link to Submitters Profile:https://hackerone.com/hillybot__ Report Title:any user could upload attachments to pentest...