Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
API key (api.semrush.com) leak in JS-file

πŸ‘‰ https://hackerone.com/reports/1218754

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Semrush
πŸ”Ή Reported By: #a_d_a_m
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 12:17pm (UTC)
Information disclosure through django debug mode

πŸ‘‰ https://hackerone.com/reports/1434276

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:56pm (UTC)
Exposed gitlab repo at https://adammanco.mtn.com/api/v4/projects

πŸ‘‰ https://hackerone.com/reports/1351359

πŸ”Ή Severity: Low
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:57pm (UTC)
CVE-2021-38314 @ https://www.mtn.co.rw

πŸ‘‰ https://hackerone.com/reports/1351341

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:58pm (UTC)
CVE-2021-38314 @ https://www.mtn.ci

πŸ‘‰ https://hackerone.com/reports/1351338

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:58pm (UTC)
firebase credentials leaks @ https://mpulse.mtnonline.com

πŸ‘‰ https://hackerone.com/reports/1351329

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:59pm (UTC)
firebase credentials leaks @ https://mtnhottseat.mtn.com.gh

πŸ‘‰ https://hackerone.com/reports/1351326

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 10:59pm (UTC)
No password length restriction in reset password endpoint at https://suppliers.mtn.cm

πŸ‘‰ https://hackerone.com/reports/1285694

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #aliyugombe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2022, 11:00pm (UTC)
IDOR Payments Status

πŸ‘‰ https://hackerone.com/reports/1538669

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Omise
πŸ”Ή Reported By: #codeslayer137
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 8:58am (UTC)
Modifying Sprunk vs eCola crew data

πŸ‘‰ https://hackerone.com/reports/1680818

πŸ”Ή Severity: Low | πŸ’° 250 USD
πŸ”Ή Reported To: Rockstar Games
πŸ”Ή Reported By: #bugstar
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 6:24pm (UTC)
Subdomain takeover of β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1457928

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #martinvw
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 6:50pm (UTC)
The dashboard is exposed in https://β–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1566758

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #alitoni224
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 6:53pm (UTC)
XSS DUE TO CVE-2020-3580

πŸ‘‰ https://hackerone.com/reports/1606068

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #cruxn3t
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 6:55pm (UTC)
Access to admininstrative resources/account via path traversal

πŸ‘‰ https://hackerone.com/reports/1326352

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #j4k3d
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 6:59pm (UTC)
RXSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1626962

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #tmz900
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:01pm (UTC)
Stored XSS at https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1620247

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #shanekag
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:04pm (UTC)
β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ_log4j - https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1631364

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #hachimanxienim
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:07pm (UTC)
solr_log4j - https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1631370

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #hachimanxienim
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:10pm (UTC)
RXSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1627616

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #tmz900
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:12pm (UTC)
Reflected cross site scripting in https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1636345

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #maskedpersian
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:30pm (UTC)
Reflected Xss in [β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ]

πŸ‘‰ https://hackerone.com/reports/1033253

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #s1m0x1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2022, 7:32pm (UTC)