bug bounty

HackerOne Bug Bounty Disclosure: b-stored-xss-on-bugzilla-mozilla-org-via-comment-edit-feature-from-non-admin-to-admin-b-r-dpars-c

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'r3dpars3c'Link to Submitters Profile:https://hackerone.com/b'r3dpars3c' Report Title:b'Stored Xss on bugzilla.mozilla.org via...

HackerOne Bug Bounty Disclosure: b-if-rate-limit-is-hit-ip-address-is-leaked-to-anyone-who-tries-to-login-b-anish-kosaraju

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'anish_kosaraju'Link to Submitters Profile:https://hackerone.com/b'anish_kosaraju' Report Title:b'If rate limit is hit,...

HackerOne Bug Bounty Disclosure: b-permanent-casb-integration-takeover-due-to-improper-access-controls-confused-deputy-problem-b-suzuka

Company Name: b'Cloudflare Public Bug Bounty' Company HackerOne URL: https://hackerone.com/cloudflare Submitted By:b'suzuka'Link to Submitters Profile:https://hackerone.com/b'suzuka' Report Title:b'Permanent CASB Integration Takeover...

HackerOne Bug Bounty Disclosure: b-unprotected-atlantis-server-at-https-b-imranhudaa

Company Name: b'8x8' Company HackerOne URL: https://hackerone.com/8x8 Submitted By:b'imranhudaa'Link to Submitters Profile:https://hackerone.com/b'imranhudaa' Report Title:b'Unprotected Atlantis Server at https://132.226..'Report Link:https://hackerone.com/reports/1895783Date Submitted:15...

HackerOne Bug Bounty Disclosure: b-able-to-see-bonus-amount-given-to-a-report-even-if-the-bounty-and-bonus-is-not-visible-to-public-or-mentioned-in-report-id-json-b-callmed

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'callmed0_4'Link to Submitters Profile:https://hackerone.com/b'callmed0_4' Report Title:b'Able to see Bonus amount given to...

HackerOne Bug Bounty Disclosure: b-multiple-cross-site-scripting-xss-vulnerabilities-in-revive-adserver-b-l-stb-t

Company Name: b'Revive Adserver' Company HackerOne URL: https://hackerone.com/revive_adserver Submitted By:b'l4stb1t'Link to Submitters Profile:https://hackerone.com/b'l4stb1t' Report Title:b'Multiple cross-site scripting (XSS) vulnerabilities in...

HackerOne Bug Bounty Disclosure: b-idor-authorization-bypass-in-lockreport-mutation-for-public-reports-b-verw-tch

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'0verw4tch'Link to Submitters Profile:https://hackerone.com/b'0verw4tch' Report Title:b'IDOR: Authorization Bypass in LockReport Mutation for...

HackerOne Bug Bounty Disclosure: b-information-disclosure-pvt-gitlab-issue-disclosing-through-gitlab-unfiltered-youtube-channel-b-mrrajputhacker

Company Name: b'GitLab' Company HackerOne URL: https://hackerone.com/gitlab Submitted By:b'mrrajputhacker2'Link to Submitters Profile:https://hackerone.com/b'mrrajputhacker2' Report Title:b'Information Disclosure - Pvt Gitlab Issue Disclosing...

HackerOne Bug Bounty Disclosure: b-request-english-versions-of-web-pages-for-enhanced-privacy-keeps-previous-grayed-out-settings-b-andreien

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'andreien'Link to Submitters Profile:https://hackerone.com/b'andreien' Report Title:b"'Request English versions of web pages for...

HackerOne Bug Bounty Disclosure: b-admin-account-panel-takeover-and-doing-actions-in-admin-panel-via-dom-based-xss-b-mouhannadlrx

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'mouhannadlrx'Link to Submitters Profile:https://hackerone.com/b'mouhannadlrx' Report Title:b'Admin account/panel takeOver and Doing actions in...

HackerOne Bug Bounty Disclosure: b-mozilla-mastodon-staging-instance-admin-api-key-disclosure-through-slack-b-griffinf

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'griffinf'Link to Submitters Profile:https://hackerone.com/b'griffinf' Report Title:b'Mozilla Mastodon Staging Instance Admin...

HackerOne Bug Bounty Disclosure: b-response-manipulation-to-enable-account-recovery-key-with-out-current-password-b-saiteja

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'saiteja1231323'Link to Submitters Profile:https://hackerone.com/b'saiteja1231323' Report Title:b'Response Manipulation to enable Account...

HackerOne Bug Bounty Disclosure: b-the-domain-is-truck-admin-eu-east-indriverapp-com-and-enter-the-management-system-of-the-blasting-mobile-phone-verification-code-b-trustworthy

Company Name: b'inDrive' Company HackerOne URL: https://hackerone.com/indrive Submitted By:b'trustworthy'Link to Submitters Profile:https://hackerone.com/b'trustworthy' Report Title:b'the domain is truck-admin.eu-east-1.indriverapp.com and Enter the...

HackerOne Bug Bounty Disclosure: b-fs-statfs-bypasses-permission-model-b-rafaelgss

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'rafaelgss'Link to Submitters Profile:https://hackerone.com/b'rafaelgss' Report Title:b'fs.statfs bypasses Permission Model'Report Link:https://hackerone.com/reports/2051224Date Submitted:10 September...

HackerOne Bug Bounty Disclosure: b-process-binding-can-bypass-the-permission-model-through-path-traversal-b-rafaelgss

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'rafaelgss'Link to Submitters Profile:https://hackerone.com/b'rafaelgss' Report Title:b'process.binding() can bypass the permission model through...