bug bounty

HackerOne Bug Bounty Disclosure: b-limited-path-traversal-in-node-js-sdk-leads-to-pii-disclosure-b-zerodivisi-n

Company Name: b'Stripe' Company HackerOne URL: https://hackerone.com/stripe Submitted By:b'zerodivisi0n'Link to Submitters Profile:https://hackerone.com/b'zerodivisi0n' Report Title:b'Limited path traversal in Node.js SDK leads...

HackerOne Bug Bounty Disclosure: b-cve-permissions-policies-can-impersonate-other-modules-in-using-module-constructor-createrequire-b-haxatron

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'haxatron1'Link to Submitters Profile:https://hackerone.com/b'haxatron1' Report Title:b'(CVE-2023-32006) Permissions policies can impersonate...

HackerOne Bug Bounty Disclosure: b-previously-created-sessions-continue-being-valid-after-fa-activation-b-tanvir-x

Company Name: b'WordPress' Company HackerOne URL: https://hackerone.com/wordpress Submitted By:b'tanvir0x'Link to Submitters Profile:https://hackerone.com/b'tanvir0x' Report Title:b'Previously created sessions continue being valid after...

HackerOne Bug Bounty Disclosure: b-draft-report-exposure-via-slack-alerting-system-for-programs-b-imranhudaa

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'imranhudaa'Link to Submitters Profile:https://hackerone.com/b'imranhudaa' Report Title:b'Draft report exposure via slack alerting system...

HackerOne Bug Bounty Disclosure: b-bypassing-garbage-collection-with-uppercase-endpoint-b-h-xploit

Company Name: b'inDrive' Company HackerOne URL: https://hackerone.com/indrive Submitted By:b'h1xploit'Link to Submitters Profile:https://hackerone.com/b'h1xploit' Report Title:b'Bypassing Garbage Collection with Uppercase Endpoint'Report Link:https://hackerone.com/reports/2078527Date...

HackerOne Bug Bounty Disclosure: b-reflected-xss-in-oauth-complete-endpoints-b-zerodivisi-n

Company Name: b'Mattermost' Company HackerOne URL: https://hackerone.com/mattermost Submitted By:b'zerodivisi0n'Link to Submitters Profile:https://hackerone.com/b'zerodivisi0n' Report Title:b'Reflected XSS in OAuth complete endpoints'Report Link:https://hackerone.com/reports/1502099Date...

HackerOne Bug Bounty Disclosure: b-missing-function-level-access-control-in-mozilla-formula-containsregular-expression-denial-of-service-cve-b-unexpectedbuffercon

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'unexpectedbuffercon_'Link to Submitters Profile:https://hackerone.com/b'unexpectedbuffercon_' Report Title:b'Missing Function Level Access Control...

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-mozaws-net-b-mikey

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'mikey96'Link to Submitters Profile:https://hackerone.com/b'mikey96' Report Title:b'Subdomain Takeover on mozaws.net'Report Link:https://hackerone.com/reports/2171494Date...

HackerOne Bug Bounty Disclosure: b-dos-in-form-submission-at-https-nextcloud-com-instant-trial-b-krrish-hackk

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'krrish_hackk'Link to Submitters Profile:https://hackerone.com/b'krrish_hackk' Report Title:b'Dos in Form Submission at https://nextcloud.com/instant-trial/'Report Link:https://hackerone.com/reports/1901396Date...

HackerOne Bug Bounty Disclosure: b-nextcloud-all-in-one-path-disclosure-of-internal-frontend-b-shuvam

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'shuvam321'Link to Submitters Profile:https://hackerone.com/b'shuvam321' Report Title:b'Nextcloud All-In-One path disclosure of internal frontend'Report...

HackerOne Bug Bounty Disclosure: b-existance-of-calendars-and-addressbooks-can-be-checked-by-unauthenticated-users-b-themarkib-x

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'themarkib0x0'Link to Submitters Profile:https://hackerone.com/b'themarkib0x0' Report Title:b'Existance of calendars and addressbooks can be...

HackerOne Bug Bounty Disclosure: b-no-rate-limit-on-forgot-password-on-https-apps-nextcloud-com-b-cyber-world

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'cyber_world_01'Link to Submitters Profile:https://hackerone.com/b'cyber_world_01' Report Title:b'No Rate Limit On Forgot Password on...

HackerOne Bug Bounty Disclosure: b-email-verification-bypass-for-manual-connection-setup-service-credentials-b-yozzo

Company Name: b'Nord Security' Company HackerOne URL: https://hackerone.com/nordsecurity Submitted By:b'yozzo_'Link to Submitters Profile:https://hackerone.com/b'yozzo_' Report Title:b'Email verification bypass for manual connection...

HackerOne Bug Bounty Disclosure: b-aws-keys-and-user-cookie-leakage-via-uninitialized-memory-leak-in-outdated-librsvg-version-in-basecamp-b-neex

Company Name: b'Basecamp' Company HackerOne URL: https://hackerone.com/basecamp Submitted By:b'neex'Link to Submitters Profile:https://hackerone.com/b'neex' Report Title:b'AWS keys and user cookie leakage via...