HackerOne Bug Bounty Disclosure: b-authentication-bypass-in-global-site-selector-allows-an-attacker-to-log-in-as-any-user-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Authentication bypass in Global Site Selector allows...

HackerOne Bug Bounty Disclosure: b-improper-handling-of-request-urls-in-nextcloud-guests-allows-guest-users-to-bypass-app-allowlist-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Improper handling of request URLs in nextcloud/guests...