bug bounty

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-https-travel-line-me-b-mheranco

Company Name: b'LY Corporation' Company HackerOne URL: https://hackerone.com/line Submitted By:b'mheranco'Link to Submitters Profile:https://hackerone.com/b'mheranco' Report Title:b'Reflected XSS on https://travel.line.me'Report Link:https://hackerone.com/reports/1880607Date Submitted:18...

HackerOne Bug Bounty Disclosure: b-authentication-bypass-in-global-site-selector-allows-an-attacker-to-log-in-as-any-user-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Authentication bypass in Global Site Selector allows...

HackerOne Bug Bounty Disclosure: b-improper-handling-of-request-urls-in-nextcloud-guests-allows-guest-users-to-bypass-app-allowlist-b-ryotak

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'ryotak'Link to Submitters Profile:https://hackerone.com/b'ryotak' Report Title:b'Improper handling of request URLs in nextcloud/guests...

HackerOne Bug Bounty Disclosure: b-error-when-editing-a-calendar-appointment-returns-stacktrace-and-query-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b'Error when editing a calendar appointment returns...

HackerOne Bug Bounty Disclosure: b-bypass-password-confirmation-via-context-dependent-access-control-cdca-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b' Bypass password confirmation via Context-dependent access...

HackerOne Bug Bounty Disclosure: b-h-oberlo-least-privileged-user-can-cancel-account-owner-s-subscription-via-post-on-payments-subscribe-b-archangel

Company Name: b'Shopify' Company HackerOne URL: https://hackerone.com/shopify Submitted By:b'archangel'Link to Submitters Profile:https://hackerone.com/b'archangel' Report Title:b" Least privileged user can cancel account...

HackerOne Bug Bounty Disclosure: b-internal-blind-server-side-request-forgery-ssrf-allows-scanning-internal-ports-b-callmed

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'callmed0_4'Link to Submitters Profile:https://hackerone.com/b'callmed0_4' Report Title:b'Internal Blind Server-Side Request Forgery...

HackerOne Bug Bounty Disclosure: b-reflected-xss-on-https-www-useast-a-tiktok-com-ug-incentive-share-hd-b-ashrafabdelrazik

Company Name: b'TikTok' Company HackerOne URL: https://hackerone.com/tiktok Submitted By:b'ashrafabdelrazik'Link to Submitters Profile:https://hackerone.com/b'ashrafabdelrazik' Report Title:b'Reflected XSS On 'Report Link:https://hackerone.com/reports/2178061Date Submitted:12 January...

HackerOne Bug Bounty Disclosure: b-users-can-access-exams-in-course-without-having-to-subscribe-to-premium-b-find-me-here

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'find_me_here'Link to Submitters Profile:https://hackerone.com/b'find_me_here' Report Title:b'Users can access exams in course without...

HackerOne Bug Bounty Disclosure: b-improper-session-management-failure-to-invalidate-old-session-after-password-change-b-technolord

Company Name: b'Teleport' Company HackerOne URL: https://hackerone.com/teleport Submitted By:b'technolord1292'Link to Submitters Profile:https://hackerone.com/b'technolord1292' Report Title:b'Improper session management - Failure to invalidate...

HackerOne Bug Bounty Disclosure: b-buffer-overflow-vulnerability-in-websocket-handling-b-dinesh-b

Company Name: b'curl' Company HackerOne URL: https://hackerone.com/curl Submitted By:b'dinesh_b'Link to Submitters Profile:https://hackerone.com/b'dinesh_b' Report Title:b'Buffer Overflow Vulnerability in WebSocket Handling'Report Link:https://hackerone.com/reports/2298307Date...

HackerOne Bug Bounty Disclosure: b-authentication-bypass-on-jetpack-sso-manager-allows-to-access-the-administration-panel-of-wordpress-without-user-interaction-b-sodium

Company Name: b'Automattic' Company HackerOne URL: https://hackerone.com/automattic Submitted By:b'sodium_'Link to Submitters Profile:https://hackerone.com/b'sodium_' Report Title:b'Authentication bypass on JetPack SSO manager -...

HackerOne Bug Bounty Disclosure: b-elasticsearch-is-currently-open-without-authentication-on-https-l-b-roland-hack

Company Name: b'U.S. Dept Of Defense' Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:b'roland_hack'Link to Submitters Profile:https://hackerone.com/b'roland_hack' Report Title:b'Elasticsearch is currently open...

HackerOne Bug Bounty Disclosure: b-admins-can-change-authentication-details-of-user-configured-external-storage-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b'Admins can change authentication details of user...