bug bounty

HackerOne Bug Bounty Disclosure: xmlrpc-php-wp-cron-php-files-are-enabled-and-will-used-for-ddos-dos-and-broutforce-users-attack-cyber-tech

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:cyber-techLink to Submitters Profile:https://hackerone.com/cyber-tech Report Title:xmlrpcphp &wp-cronphp files are enabled, and will...

HackerOne Bug Bounty Disclosure: idor-on-graphql-queries-billingdocumentdownload-and-billdetails-blaklis

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:blaklisLink to Submitters Profile:https://hackerone.com/blaklis Report Title:IDOR on GraphQL queries BillingDocumentDownload and BillDetailsReport...

HackerOne Bug Bounty Disclosure: account-creation-with-invalid-email-addresses-email-is-accepting-and-d-a-line-termination-chars-resett-r

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:resett3rLink to Submitters Profile:https://hackerone.com/resett3r Report Title:Account creation with invalid email addresses /...

HackerOne Bug Bounty Disclosure: hackerone-saml-signup-domain-enforcement-bypass-results-in-unauthorized-access-to-hackerone-pullrequest-organization–xacb

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:0xacbLink to Submitters Profile:https://hackerone.com/0xacb Report Title:HackerOne SAML signup domain enforcement bypass results...

HackerOne Bug Bounty Disclosure: b-memory-corruption-via-large-pixels-b-mr-r-boot

Company Name: b'Infogram' Company HackerOne URL: https://hackerone.com/infogram Submitted By:b'mr_r3boot'Link to Submitters Profile:https://hackerone.com/b'mr_r3boot' Report Title:b'Memory Corruption via Large Pixels'Report Link:https://hackerone.com/reports/282518Date Submitted:01...

HackerOne Bug Bounty Disclosure: b-default-credentials-at-https-b-forcedrofes

Company Name: b'Trellix' Company HackerOne URL: https://hackerone.com/trellix Submitted By:b'forcedrofes'Link to Submitters Profile:https://hackerone.com/b'forcedrofes' Report Title:b'default credentials at https://52.42.105.71/'Report Link:https://hackerone.com/reports/2160178Date Submitted:01 February...

HackerOne Bug Bounty Disclosure: b-port-smpt-open-can-send-any-mail-remotely-from-the-internal-mail-users-to-company-mail-id-s-b-harshniture

Company Name: b'SideFX' Company HackerOne URL: https://hackerone.com/sidefx Submitted By:b'harshniture12'Link to Submitters Profile:https://hackerone.com/b'harshniture12' Report Title:b"Port 587 SMPT Open: Can send any...

HackerOne Bug Bounty Disclosure: b-exposed-cdn-access-token-allows-modification-of-all-newly-uploaded-snapmatic-photos-b-bugstar

Company Name: b'Rockstar Games' Company HackerOne URL: https://hackerone.com/rockstargames Submitted By:b'bugstar'Link to Submitters Profile:https://hackerone.com/b'bugstar' Report Title:b'Exposed CDN access token allows modification...

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-help-shopify-com-b-ssilvass

Company Name: b'Shopify' Company HackerOne URL: https://hackerone.com/shopify Submitted By:b'ssilvass'Link to Submitters Profile:https://hackerone.com/b'ssilvass' Report Title:b'Reflected XSS on help.shopify.com'Report Link:https://hackerone.com/reports/1940245Date Submitted:25 January...

HackerOne Bug Bounty Disclosure: b-lack-of-tenant-scoping-enables-limited-cross-tenant-data-querying-and-mutation-b-tushar-rec-n

Company Name: b'Enjin' Company HackerOne URL: https://hackerone.com/enjin Submitted By:b'tushar_rec0n'Link to Submitters Profile:https://hackerone.com/b'tushar_rec0n' Report Title:b'Lack of Tenant Scoping Enables Limited Cross-Tenant...