bug bounty

HackerOne Bug Bounty Disclosure: attacker-can-add-itself-as-admin-user-and-can-also-change-privileges-of-existing-users-dishant-singh

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:dishant_singhLink to Submitters Profile:https://hackerone.com/dishant_singh Report Title:Attacker can Add itself...

HackerOne Bug Bounty Disclosure: improper-authentication-login-without-registration-with-any-user-at-archyxsec

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:archyxsecLink to Submitters Profile:https://hackerone.com/archyxsec Report Title:Improper Authentication (Login without...

HackerOne Bug Bounty Disclosure: -leaking-pii-of-tour-visitors-names-email-addresses-phone-numbers-via-misconfigured-record-permissions-oxylis

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:oxylisLink to Submitters Profile:https://hackerone.com/oxylis Report Title: leaking PII of...

HackerOne Bug Bounty Disclosure: patch-method-manipulation-allowing-the-users-to-escalate-their-functionalities-and-edit-upgrade-downgrade-api-keys-settings-which-is-not-allowed-bugsv

Company Name: Frontegg Company HackerOne URL: https://hackerone.com/frontegg Submitted By:bugsv2Link to Submitters Profile:https://hackerone.com/bugsv2 Report Title:PATCH method manipulation allowing the users to...

HackerOne Bug Bounty Disclosure: bypassing-the-block-of-security-domain-restriction-and-normally-invite-blocked-domains-with-special-characters-bugsv

Company Name: Frontegg Company HackerOne URL: https://hackerone.com/frontegg Submitted By:bugsv2Link to Submitters Profile:https://hackerone.com/bugsv2 Report Title:Bypassing the block of Security Domain Restriction...

HackerOne Bug Bounty Disclosure: steal-any-user-in-your-orgs-private-github-token-by-pointing-the-gh-integration-at-an-attacker-controlled-ghe-instance-archangel

Company Name: New Relic Company HackerOne URL: https://hackerone.com/newrelic Submitted By:archangelLink to Submitters Profile:https://hackerone.com/archangel Report Title:Steal any user in your orgs...

HackerOne Bug Bounty Disclosure: missing-authorization-check-on-view-permissions-for-alerting-conditions-via-internal-api-accounts-xxxxxxx-policies-yyyyyyy-conditions-offs-endpoint-archangel

Company Name: New Relic Company HackerOne URL: https://hackerone.com/newrelic Submitted By:archangelLink to Submitters Profile:https://hackerone.com/archangel Report Title:Missing Authorization check on View permissions...

HackerOne Bug Bounty Disclosure: user-without-view-modify-delete-permissions-on-destinations-can-view-modify-delete-destinations-archangel

Company Name: New Relic Company HackerOne URL: https://hackerone.com/newrelic Submitted By:archangelLink to Submitters Profile:https://hackerone.com/archangel Report Title:User without "View/Modify/Delete" permissions on "Destinations"...

HackerOne Bug Bounty Disclosure: github-app-link-takeover-listed-on-hxxps-docs-doppler-com-docs-github-actions-page-w-shi

Company Name: Doppler Company HackerOne URL: https://hackerone.com/doppler Submitted By:w3shiLink to Submitters Profile:https://hackerone.com/w3shi Report Title:Github app(link) Takeover Listed on "hXXps://docsdopplercom/docs/github-actions" pageReport...

HackerOne Bug Bounty Disclosure: unauthorized-access-to-offline-publication-cover-pages-via-source-document-id-giwadaoud

Company Name: Publitas Company HackerOne URL: https://hackerone.com/publitas Submitted By:giwadaoudLink to Submitters Profile:https://hackerone.com/giwadaoud Report Title:Unauthorized Access to Offline Publication Cover Pages...

HackerOne Bug Bounty Disclosure: insecure-s-bucket-exposing-git-directory-in-mozilla-foundation-infographics-project-psycho

Company Name: Mozilla Critical Services Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:psycho_012Link to Submitters Profile:https://hackerone.com/psycho_012 Report Title:Insecure S3 Bucket Exposing Git...

HackerOne Bug Bounty Disclosure: session-doesn-t-expire-after-fa-and-also-other-session-can-change-passsword–xchoudhary

Company Name: SideFX Company HackerOne URL: https://hackerone.com/sidefx Submitted By:0xchoudharyLink to Submitters Profile:https://hackerone.com/0xchoudhary Report Title:Session Doesn't expire after 2fa and also...

HackerOne Bug Bounty Disclosure: -drivers-can-access-the-customers-phone-number-current-location-without-getting-their-offer-accepted-bugsv

Company Name: inDrive Company HackerOne URL: https://hackerone.com/indrive Submitted By:bugsv2Link to Submitters Profile:https://hackerone.com/bugsv2 Report Title:# Drivers can access the customers phone...