Bug Bounty

HackerOne Bug Bounty Disclosure: b-exposed-cdn-access-token-allows-modification-of-all-newly-uploaded-snapmatic-photos-b-bugstar

Company Name: b'Rockstar Games' Company HackerOne URL: https://hackerone.com/rockstargames Submitted By:b'bugstar'Link to Submitters Profile:https://hackerone.com/b'bugstar' Report Title:b'Exposed CDN access token allows modification...

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-help-shopify-com-b-ssilvass

Company Name: b'Shopify' Company HackerOne URL: https://hackerone.com/shopify Submitted By:b'ssilvass'Link to Submitters Profile:https://hackerone.com/b'ssilvass' Report Title:b'Reflected XSS on help.shopify.com'Report Link:https://hackerone.com/reports/1940245Date Submitted:25 January...

HackerOne Bug Bounty Disclosure: b-lack-of-tenant-scoping-enables-limited-cross-tenant-data-querying-and-mutation-b-tushar-rec-n

Company Name: b'Enjin' Company HackerOne URL: https://hackerone.com/enjin Submitted By:b'tushar_rec0n'Link to Submitters Profile:https://hackerone.com/b'tushar_rec0n' Report Title:b'Lack of Tenant Scoping Enables Limited Cross-Tenant...

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-https-travel-line-me-b-mheranco

Company Name: b'LY Corporation' Company HackerOne URL: https://hackerone.com/line Submitted By:b'mheranco'Link to Submitters Profile:https://hackerone.com/b'mheranco' Report Title:b'Reflected XSS on https://travel.line.me'Report Link:https://hackerone.com/reports/1880607Date Submitted:18...

HackerOne Bug Bounty Disclosure: b-improper-handling-of-request-urls-in-nextcloud-guests-allows-guest-users-to-bypass-app-allowlist-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Improper handling of request URLs in nextcloud/guests...

HackerOne Bug Bounty Disclosure: b-authentication-bypass-in-global-site-selector-allows-an-attacker-to-log-in-as-any-user-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Authentication bypass in Global Site Selector allows...

HackerOne Bug Bounty Disclosure: b-error-when-editing-a-calendar-appointment-returns-stacktrace-and-query-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b'Error when editing a calendar appointment returns...

HackerOne Bug Bounty Disclosure: b-bypass-password-confirmation-via-context-dependent-access-control-cdca-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b' Bypass password confirmation via Context-dependent access...

HackerOne Bug Bounty Disclosure: b-h-oberlo-least-privileged-user-can-cancel-account-owner-s-subscription-via-post-on-payments-subscribe-b-archangel

Company Name: b'Shopify' Company HackerOne URL: https://hackerone.com/shopify Submitted By:b'archangel'Link to Submitters Profile:https://hackerone.com/b'archangel' Report Title:b" Least privileged user can cancel account...

HackerOne Bug Bounty Disclosure: b-internal-blind-server-side-request-forgery-ssrf-allows-scanning-internal-ports-b-callmed

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'callmed0_4'Link to Submitters Profile:https://hackerone.com/b'callmed0_4' Report Title:b'Internal Blind Server-Side Request Forgery...

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-https-www-useast-a-tiktok-com-ug-incentive-share-hd-b-ashrafabdelrazik

Company Name: b'TikTok' Company HackerOne URL: https://hackerone.com/tiktok Submitted By:b'ashrafabdelrazik'Link to Submitters Profile:https://hackerone.com/b'ashrafabdelrazik' Report Title:b'Reflected XSS On 'Report Link:https://hackerone.com/reports/2178061Date Submitted:12 January...

HackerOne Bug Bounty Disclosure: b-users-can-access-exams-in-course-without-having-to-subscribe-to-premium-b-find-me-here

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'find_me_here'Link to Submitters Profile:https://hackerone.com/b'find_me_here' Report Title:b'Users can access exams in course without...