Bug Bounty

HackerOne Bug Bounty Disclosure: std-process-command-batch-files-argument-escaping-could-be-bypassed-with-trailing-whitespace-or-periods–xpl-r-r

Company Name: Internet Bug Bounty Company HackerOne URL: https://hackerone.com/ibb Submitted By:4xpl0r3rLink to Submitters Profile:https://hackerone.com/4xpl0r3r Report Title:`std::process::Command` batch files argument escaping...

HackerOne Bug Bounty Disclosure: external-storage-global-credentials-returned-to-the-client-side-in-plaintext-tuyenee

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:tuyeneeLink to Submitters Profile:https://hackerone.com/tuyenee Report Title:External storage - global credentials returned to...

HackerOne Bug Bounty Disclosure: csrftoken-not-unique-to-session-or-specific-user-and-csrfmiddlewaretoken-can-be-altered-bashbdeer

Company Name: Mozilla Company HackerOne URL: https://hackerone.com/mozilla Submitted By:bashbdeerLink to Submitters Profile:https://hackerone.com/bashbdeer Report Title:csrftoken not unique to session or specific...

HackerOne Bug Bounty Disclosure: reflected-xss-in-hxxps-www-acronis-com-products-cyber-protect-trial-tomblorg

Company Name: Acronis Company HackerOne URL: https://hackerone.com/acronis Submitted By:tomblorgLink to Submitters Profile:https://hackerone.com/tomblorg Report Title:Reflected XSS in hXXps://wwwacroniscom/products/cyber-protect/trial/Report Link:https://hackerone.com/reports/1891926Date Submitted:20 November...

HackerOne Bug Bounty Disclosure: a-potential-risk-in-the-cloudfrontextensionsconsole-which-can-be-used-to-privilege-escalation-zolaer

Company Name: AWS VDP Company HackerOne URL: https://hackerone.com/aws_vdp Submitted By:zolaer9527Link to Submitters Profile:https://hackerone.com/zolaer9527 Report Title:A potential risk in the cloudFrontExtensionsConsole...

HackerOne Bug Bounty Disclosure: hackerone-supports-accounts-organitation-takeover-madara

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:madara_Link to Submitters Profile:https://hackerone.com/madara_ Report Title:Hackerone supports accounts organitation takeoverReport Link:https://hackerone.com/reports/2798380Date Submitted:19...

HackerOne Bug Bounty Disclosure: heap-buffer-overread-in-contains-whitespace-when-calling-parser-validate-after-supplying-a-maliciously-crafted-buffer-to-parser-parse-l-thaxor

Company Name: Cosmos Company HackerOne URL: https://hackerone.com/cosmos Submitted By:l33thaxorLink to Submitters Profile:https://hackerone.com/l33thaxor Report Title:Heap-Buffer-Overread in contains_whitespace when calling parser_validate after...

HackerOne Bug Bounty Disclosure: unauthenticated-phpinfo-files-could-lead-to-ability-file-read-at-h-f-n-ips-mtn-co-ug-offensiveops

Company Name: MTN Group Company HackerOne URL: https://hackerone.com/mtn_group Submitted By:offensiveopsLink to Submitters Profile:https://hackerone.com/offensiveops Report Title:Unauthenticated phpinfo()files could lead to ability...

HackerOne Bug Bounty Disclosure: mail-auto-configurator-can-be-tricked-into-sending-account-information-to-wrong-servers-shushangw

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:shushangwLink to Submitters Profile:https://hackerone.com/shushangw Report Title:Mail auto configurator can be tricked into...

HackerOne Bug Bounty Disclosure: attachments-folder-for-text-app-is-accessible-on-files-drop-password-protected-shares-lukasreschke

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:lukasreschkeLink to Submitters Profile:https://hackerone.com/lukasreschke Report Title:Attachments folder for Text app is accessible...

HackerOne Bug Bounty Disclosure: availability-impact-from-exploiting-project-name-vulnerabilities-mr-root

Company Name: Doppler Company HackerOne URL: https://hackerone.com/doppler Submitted By:mr_root_0101Link to Submitters Profile:https://hackerone.com/mr_root_0101 Report Title:Availability Impact from Exploiting Project Name VulnerabilitiesReport...