Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
PYTHON: CWE-079 - Add query for email injection

πŸ‘‰ https://hackerone.com/reports/1602237

πŸ”Ή Severity: High | πŸ’° 4,500 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #jorgectf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 5:52pm (UTC)
IDOR - Delete technical skill assessment result & Gained Badges result of any user

πŸ‘‰ https://hackerone.com/reports/1592587

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: LinkedIn
πŸ”Ή Reported By: #sachin_kumar_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 7:29pm (UTC)
No rate limit on subscribe form

πŸ‘‰ https://hackerone.com/reports/1708824

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #happykira0x1
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: October 5, 2022, 8:55pm (UTC)
Blind SSRF in social-plugins.line.me

πŸ‘‰ https://hackerone.com/reports/833758

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: LINE
πŸ”Ή Reported By: #sirleeroyjenkins
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 6, 2022, 9:25am (UTC)
SSRF on https://www.β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/crossdomain.php via url parameter

πŸ‘‰ https://hackerone.com/reports/971590

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Sony
πŸ”Ή Reported By: #n0x496n
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 6, 2022, 3:44pm (UTC)
Path Traversal issue at https://β–ˆβ–ˆβ–ˆβ–ˆ/blaze/

πŸ‘‰ https://hackerone.com/reports/1320084

πŸ”Ή Severity: High
πŸ”Ή Reported To: Sony
πŸ”Ή Reported By: #lu3ky-13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 6, 2022, 3:53pm (UTC)
SQL Injection through /include/findusers.php

πŸ‘‰ https://hackerone.com/reports/1081145

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: ImpressCMS
πŸ”Ή Reported By: #egix
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 6, 2022, 6:51pm (UTC)
Remote Command Execution via Github import

πŸ‘‰ https://hackerone.com/reports/1679624

πŸ”Ή Severity: Critical | πŸ’° 33,510 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #vakzz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 6, 2022, 8:19pm (UTC)
Relative Path Traversal vulnerability in fabric-private-chaincode

πŸ‘‰ https://hackerone.com/reports/1690377

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Hyperledger
πŸ”Ή Reported By: #bhaskar_ram
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: October 9, 2022, 7:41am (UTC)
Email Address Exposure via Gratipay Migration Tool

πŸ‘‰ https://hackerone.com/reports/1727044

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Liberapay
πŸ”Ή Reported By: #suprnova
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 9, 2022, 11:50am (UTC)
CORS Misconfiguration on trust.yelp.com

πŸ‘‰ https://hackerone.com/reports/1716286

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #ajayjachak
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: October 10, 2022, 4:59am (UTC)
Deny of service via malicious Content-Type

πŸ‘‰ https://hackerone.com/reports/1715536

πŸ”Ή Severity: High
πŸ”Ή Reported To: Fastify
πŸ”Ή Reported By: #bitk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 10, 2022, 8:43am (UTC)
Stored XSS in the ticketing system

πŸ‘‰ https://hackerone.com/reports/1694037

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #codeslayer137
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 10, 2022, 10:35pm (UTC)
Autofill/Autosave password on login

πŸ‘‰ https://hackerone.com/reports/1720621

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #zero_990
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: October 11, 2022, 5:15pm (UTC)
IDOR [mtnmobad.mtnbusiness.com.ng]

πŸ‘‰ https://hackerone.com/reports/1698006

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #insomnia_hax
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 7:18am (UTC)
DoS of https://research.adobe.com/ via CVE-2018-6389 exploitation

πŸ‘‰ https://hackerone.com/reports/1511628

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Adobe
πŸ”Ή Reported By: #shirshak
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 9:52am (UTC)
Misconfigured build on websites "abuse.cloudflare.com"

πŸ‘‰ https://hackerone.com/reports/1624911

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #paradessia_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 10:02am (UTC)
mail.acronis.com is vulnerable to zero day vulnerability CVE-2022-41040

πŸ‘‰ https://hackerone.com/reports/1719719

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: Acronis
πŸ”Ή Reported By: #aplis
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 5:12pm (UTC)
Cross-site scripting on api.collabs.shopify.com

πŸ‘‰ https://hackerone.com/reports/1672459

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #kun_19
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 6:12pm (UTC)
XSS seems to work again after change to linkpop at https://linkpop.com/testnaglinagli

πŸ‘‰ https://hackerone.com/reports/1569940

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #nagli
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 6:22pm (UTC)
Staff can create workflows in Shopify Admin without apps permission

πŸ‘‰ https://hackerone.com/reports/1521336

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #jmp_35p
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 13, 2022, 6:53pm (UTC)