Bug Bounty

HackerOne Bug Bounty Disclosure: desktop-client-can-be-tricked-into-opening/executing-local-files-when-clicking-a-nc://open/-linkbylukasreschke

Programme HackerOne Nextcloud Nextcloud Submitted by lukasreschke lukasreschke Report Desktop client can be tricked into opening/executing local files when clicking...

HackerOne Bug Bounty Disclosure: double-forward-slash-breaks-server-side-restrictions-&-allows-access-to-prohibited-services-from-a-partner-accountbyashwarya

Programme HackerOne EXNESS EXNESS Submitted by ashwarya ashwarya Report Double forward slash breaks server-side restrictions & allows access to prohibited...

HackerOne Bug Bounty Disclosure: verification-process-done-using-different-documents-without-corresponding-to-user-information-/-user-information-can-be-changed-after-verificationbysiddharthamx

Programme HackerOne EXNESS EXNESS Submitted by siddharthamx siddharthamx Report Verification process done using different documents without corresponding to user information...

HackerOne Bug Bounty Disclosure: github-apps-can-use-scoped-user-to-server-tokens-to-obtain-full-access-to-user’s-projects-in-project-v2-graphql-apibyahacker1

Programme HackerOne GitHub GitHub Submitted by ahacker1 ahacker1 Report Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to...