bug bounty

HackerOne Bug Bounty Disclosure: html-injection-possible-with-soft-email-confirmations-when-administrator-manually-confirms-attacker-email-address-cryptopone

Company Name: GitLab Company HackerOne URL: https://hackerone.com/gitlab Submitted By:cryptoponeLink to Submitters Profile:https://hackerone.com/cryptopone Report Title:HTML injection possible with soft email confirmations...

HackerOne Bug Bounty Disclosure: user-api-key-leakage-in-github-commit-leads-to-unauthorized-access-to-sql-telemetry-mozilla-org-anhchangmutrang

Company Name: Mozilla Company HackerOne URL: https://hackerone.com/mozilla Submitted By:anhchangmutrangLink to Submitters Profile:https://hackerone.com/anhchangmutrang Report Title:User API Key leakage in Github commit...

HackerOne Bug Bounty Disclosure: reflected-xss-in-hxxps-nin-mtn-ng-nin-success-message-lol-nin-vulnerable-hazemhussien

Company Name: MTN Group Company HackerOne URL: https://hackerone.com/mtn_group Submitted By:hazemhussien99Link to Submitters Profile:https://hackerone.com/hazemhussien99 Report Title:Reflected XSS in hXXps://ninmtnng/nin/success?message=lol&nin=Report Link:https://hackerone.com/reports/2039384Date Submitted:05...

HackerOne Bug Bounty Disclosure: external-service-interaction-http-hesham-elsheme

Company Name: AWS VDP Company HackerOne URL: https://hackerone.com/aws_vdp Submitted By:hesham_elshemeLink to Submitters Profile:https://hackerone.com/hesham_elsheme Report Title:External service interaction (HTTP)Report Link:https://hackerone.com/reports/2731133Date Submitted:04...

HackerOne Bug Bounty Disclosure: the-initial-e-ee-password-generated-by-rocket-chat-mobile-can-be-recovered-in-a-practical-timescale-h

Company Name: Rocket.Chat Company HackerOne URL: https://hackerone.com/rocket_chat Submitted By:h0011Link to Submitters Profile:https://hackerone.com/h0011 Report Title:The initial E2EE password generated by RocketChat...

HackerOne Bug Bounty Disclosure: -switch-pia-mk-dx-stack-buffer-overflow-and-potential-rce-in-pia-lan-ldn-possibly-nex-room-info-deserialization-regginator

Company Name: Nintendo Company HackerOne URL: https://hackerone.com/nintendo Submitted By:regginatorLink to Submitters Profile:https://hackerone.com/regginator Report Title: Stack buffer overflow and potential RCE...

HackerOne Bug Bounty Disclosure: inviting-collaborator-using-email-disclose-the-hackerone-account-related-to-the-user-raymatp

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:raymatpLink to Submitters Profile:https://hackerone.com/raymatp Report Title:inviting collaborator using email disclose the hackerone...

HackerOne Bug Bounty Disclosure: issue-with-vdp-program-s-transition-to-private-status-and-missing-warning-labels-on-org-invitation-callmed

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:callmed0_4Link to Submitters Profile:https://hackerone.com/callmed0_4 Report Title:Issue with VDP Program's Transition to Private...