bug bounty

HackerOne Bug Bounty Disclosure: b-names-not-completely-redacted-despite-redact-the-names-of-the-involved-users-is-selected-b-japz

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'japz'Link to Submitters Profile:https://hackerone.com/b'japz' Report Title:b'Names not completely redacted despite "Redact the...

HackerOne Bug Bounty Disclosure: b-idor-delete-all-licenses-and-certifications-from-users-account-using-createorupdatehackercertification-graphql-query-b-callmed

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'callmed0_4'Link to Submitters Profile:https://hackerone.com/b'callmed0_4' Report Title:b'IDOR - Delete all Licenses and certifications...

HackerOne Bug Bounty Disclosure: b-unsanitized-input-goes-to-regex-function-leads-to-redos-that-make-request-hangs-b-shin

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'shin24'Link to Submitters Profile:https://hackerone.com/b'shin24' Report Title:b'unsanitized input goes to regex...

HackerOne Bug Bounty Disclosure: b-stored-xss-on-promo-indrive-com-b-kristoferent

Company Name: b'inDrive' Company HackerOne URL: https://hackerone.com/indrive Submitted By:b'kristoferent'Link to Submitters Profile:https://hackerone.com/b'kristoferent' Report Title:b'Stored XSS on promo.indrive.com'Report Link:https://hackerone.com/reports/2051085Date Submitted:28 August...

HackerOne Bug Bounty Disclosure: b-http-request-smuggling-via-empty-headers-separated-by-cr-b-yadhukrishnam

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'yadhukrishnam'Link to Submitters Profile:https://hackerone.com/b'yadhukrishnam' Report Title:b'HTTP Request Smuggling via Empty...

HackerOne Bug Bounty Disclosure: b-staff-and-triage-can-modify-the-initial-post-of-a-report-including-of-already-disclosed-reports-b-zerotea

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'zerotea'Link to Submitters Profile:https://hackerone.com/b'zerotea' Report Title:b'Staff and Triage can modify the initial...

HackerOne Bug Bounty Disclosure: b-improper-access-control-on-linkedin-page-b-cybergoddess

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'cybergoddess'Link to Submitters Profile:https://hackerone.com/b'cybergoddess' Report Title:b'Improper access control on Linkedin Page'Report Link:https://hackerone.com/reports/1587246Date...

HackerOne Bug Bounty Disclosure: b-a-unverified-user-can-post-newsletter-which-is-not-allowed-through-application-ui-b-tushar

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'tushar6378'Link to Submitters Profile:https://hackerone.com/b'tushar6378' Report Title:b'A Unverified User Can Post Newsletter (Which...

HackerOne Bug Bounty Disclosure: b-attackers-can-use-trial-premium-only-by-paying-idr-from-the-original-price-of-idr-per-month-b-find-me-here

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'find_me_here'Link to Submitters Profile:https://hackerone.com/b'find_me_here' Report Title:b'Attackers can use TRIAL Premium only by...

HackerOne Bug Bounty Disclosure: b-an-attacker-can-flag-draft-job-posts-and-can-disclose-the-draft-job-posts-details-similar-to-resolved-report-b-tushar

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'tushar6378'Link to Submitters Profile:https://hackerone.com/b'tushar6378' Report Title:b'An Attacker Can Flag Draft Job Posts...

HackerOne Bug Bounty Disclosure: b-cross-origin-resource-sharing-arbitrary-origin-trusted-b-kalendra

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'kalendra456'Link to Submitters Profile:https://hackerone.com/b'kalendra456' Report Title:b'Cross-origin resource sharing: arbitrary origin trusted'Report Link:https://hackerone.com/reports/1848730Date...

HackerOne Bug Bounty Disclosure: b-insecure-storage-of-information-you-can-view-any-file-uploaded-to-the-server-without-authentication-and-only-with-a-single-link-b-h

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'h03'Link to Submitters Profile:https://hackerone.com/b'h03' Report Title:b'insecure storage of information, you can view...

HackerOne Bug Bounty Disclosure: b-mk-dx-improper-metadata-validation-b-crazy-man

Company Name: b'Nintendo' Company HackerOne URL: https://hackerone.com/nintendo Submitted By:b'crazy_man123'Link to Submitters Profile:https://hackerone.com/b'crazy_man123' Report Title:b' Improper metadata validation 2'Report Link:https://hackerone.com/reports/1812732Date Submitted:17...

HackerOne Bug Bounty Disclosure: b-mk-dx-improper-metadata-parsing-b-crazy-man

Company Name: b'Nintendo' Company HackerOne URL: https://hackerone.com/nintendo Submitted By:b'crazy_man123'Link to Submitters Profile:https://hackerone.com/b'crazy_man123' Report Title:b' Improper metadata parsing'Report Link:https://hackerone.com/reports/1688309Date Submitted:17 August...

HackerOne Bug Bounty Disclosure: b-renaming-aliasing-relative-symbolic-links-potentially-redirects-them-to-supposedly-inaccessible-locations-b-tniessen

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'tniessen'Link to Submitters Profile:https://hackerone.com/b'tniessen' Report Title:b'Renaming/aliasing relative symbolic links potentially redirects them...