Bug Bounty

HackerOne Bug Bounty Disclosure: b-potential-spoofing-risk-through-firefox-private-relay-service-b-nicholas-cw

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'nicholas_cw'Link to Submitters Profile:https://hackerone.com/b'nicholas_cw' Report Title:b'Potential Spoofing Risk through Firefox...

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-one-of-the-subdomain-under-mozaws-net-b-holybugx

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'holybugx'Link to Submitters Profile:https://hackerone.com/b'holybugx' Report Title:b'Subdomain takeover on one of...

HackerOne Bug Bounty Disclosure: b-admin-mytva-com-customer-lookup-and-internal-notes-bypass-b-itssixtynein

Company Name: b'Tennessee Valley Authority' Company HackerOne URL: https://hackerone.com/tennessee-valley-authority Submitted By:b'itssixtynein'Link to Submitters Profile:https://hackerone.com/b'itssixtynein' Report Title:b'Admin.MyTVA.com Customer lookup and internal...

HackerOne Bug Bounty Disclosure: b-limited-path-traversal-in-node-js-sdk-leads-to-pii-disclosure-b-zerodivisi-n

Company Name: b'Stripe' Company HackerOne URL: https://hackerone.com/stripe Submitted By:b'zerodivisi0n'Link to Submitters Profile:https://hackerone.com/b'zerodivisi0n' Report Title:b'Limited path traversal in Node.js SDK leads...

HackerOne Bug Bounty Disclosure: b-cve-permissions-policies-can-impersonate-other-modules-in-using-module-constructor-createrequire-b-haxatron

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'haxatron1'Link to Submitters Profile:https://hackerone.com/b'haxatron1' Report Title:b'(CVE-2023-32006) Permissions policies can impersonate...

HackerOne Bug Bounty Disclosure: b-previously-created-sessions-continue-being-valid-after-fa-activation-b-tanvir-x

Company Name: b'WordPress' Company HackerOne URL: https://hackerone.com/wordpress Submitted By:b'tanvir0x'Link to Submitters Profile:https://hackerone.com/b'tanvir0x' Report Title:b'Previously created sessions continue being valid after...

HackerOne Bug Bounty Disclosure: b-draft-report-exposure-via-slack-alerting-system-for-programs-b-imranhudaa

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'imranhudaa'Link to Submitters Profile:https://hackerone.com/b'imranhudaa' Report Title:b'Draft report exposure via slack alerting system...

HackerOne Bug Bounty Disclosure: b-bypassing-garbage-collection-with-uppercase-endpoint-b-h-xploit

Company Name: b'inDrive' Company HackerOne URL: https://hackerone.com/indrive Submitted By:b'h1xploit'Link to Submitters Profile:https://hackerone.com/b'h1xploit' Report Title:b'Bypassing Garbage Collection with Uppercase Endpoint'Report Link:https://hackerone.com/reports/2078527Date...

HackerOne Bug Bounty Disclosure: b-reflected-xss-in-oauth-complete-endpoints-b-zerodivisi-n

Company Name: b'Mattermost' Company HackerOne URL: https://hackerone.com/mattermost Submitted By:b'zerodivisi0n'Link to Submitters Profile:https://hackerone.com/b'zerodivisi0n' Report Title:b'Reflected XSS in OAuth complete endpoints'Report Link:https://hackerone.com/reports/1502099Date...

HackerOne Bug Bounty Disclosure: b-missing-function-level-access-control-in-mozilla-formula-containsregular-expression-denial-of-service-cve-b-unexpectedbuffercon

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'unexpectedbuffercon_'Link to Submitters Profile:https://hackerone.com/b'unexpectedbuffercon_' Report Title:b'Missing Function Level Access Control...

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-mozaws-net-b-mikey

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'mikey96'Link to Submitters Profile:https://hackerone.com/b'mikey96' Report Title:b'Subdomain Takeover on mozaws.net'Report Link:https://hackerone.com/reports/2171494Date...

HackerOne Bug Bounty Disclosure: b-nextcloud-all-in-one-path-disclosure-of-internal-frontend-b-shuvam

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'shuvam321'Link to Submitters Profile:https://hackerone.com/b'shuvam321' Report Title:b'Nextcloud All-In-One path disclosure of internal frontend'Report...