Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Account takeover on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1627961

πŸ”Ή Severity: High | πŸ’° 500 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #nightm4re
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:05pm (UTC)
IDOR leaking PII data via VendorId parameter

πŸ‘‰ https://hackerone.com/reports/1690044

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0x1int
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:24pm (UTC)
Account Takeover and Information update due to cross site request forgery via POST β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/registration/my-account.cfm

πŸ‘‰ https://hackerone.com/reports/1626356

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #snifyak
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:28pm (UTC)
Blind SSRF via image upload URL downloader on https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/

πŸ‘‰ https://hackerone.com/reports/1691501

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0x1int
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:36pm (UTC)
[HTA2] Receivingβ–ˆβ–ˆβ–ˆβ–ˆ access request on @wearehackerone.com email address

πŸ‘‰ https://hackerone.com/reports/715740

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #jr0ch17
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:41pm (UTC)
[hta3] Chain of ESI Injection & Reflected XSS leading to Account Takeover on [β–ˆβ–ˆβ–ˆ]

πŸ‘‰ https://hackerone.com/reports/1073780

πŸ”Ή Severity: High | πŸ’° 750 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #jr0ch17
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:44pm (UTC)
Local file read at https://β–ˆβ–ˆβ–ˆβ–ˆ/ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1626210

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #sudi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:51pm (UTC)
Broken access discloses users and PII at https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1624374

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #g4mb4
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 1:53pm (UTC)
Found Origin IP's Lead To Access β–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1556808

πŸ”Ή Severity: Low
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #ibrahim0936356
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 2:28pm (UTC)
Subdomain Takeover at https://β–ˆβ–ˆ.get8x8.com/

πŸ‘‰ https://hackerone.com/reports/1697402

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #testingforbugs
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 3:05pm (UTC)
SSRF to read AWS metaData at https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1624140

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #720922
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 3:12pm (UTC)
πŸ‘1
Authentication bypass leads to Information Disclosure at U.S Air Force "https://β–ˆβ–ˆβ–ˆ"

πŸ‘‰ https://hackerone.com/reports/1690548

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #ludv1k
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 5:01pm (UTC)
Unauthenticated PII leak on verified/requested to be verified profiles on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/app/org/{id}/profile/{id}/version/{id} [HtUS]

πŸ‘‰ https://hackerone.com/reports/1627962

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #shreky
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 5:04pm (UTC)
.git folder exposed [HtUS]

πŸ‘‰ https://hackerone.com/reports/1624157

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #sudi
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: October 14, 2022, 5:44pm (UTC)
Unauthenticated SQL Injection at β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1626226

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0xd0ff9
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 5:54pm (UTC)
Host Header Injection on https://β–ˆβ–ˆβ–ˆ/β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/Account/ForgotPassword

πŸ‘‰ https://hackerone.com/reports/1679969

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0x1int
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 14, 2022, 6:03pm (UTC)
Otp bypass in verifying nin

πŸ‘‰ https://hackerone.com/reports/1314172

πŸ”Ή Severity: High
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #mr_sparrow
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 17, 2022, 6:27am (UTC)
XSS in www.shopify.com/markets?utm_source=

πŸ‘‰ https://hackerone.com/reports/1699762

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #noblesix
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 18, 2022, 7:14am (UTC)
CVE-2017-5929: Hyperledger - Arbitrary Deserialization of Untrusted Data

πŸ‘‰ https://hackerone.com/reports/1739099

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Hyperledger
πŸ”Ή Reported By: #mik-patient
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 18, 2022, 3:36pm (UTC)
TikTok Account Creation Date Information Disclosure

πŸ‘‰ https://hackerone.com/reports/1562020

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #f15
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 18, 2022, 8:50pm (UTC)
Access to private file's of helpdesk.

πŸ‘‰ https://hackerone.com/reports/804534

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Lark Technologies
πŸ”Ή Reported By: #imran_nisar
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 18, 2022, 9:05pm (UTC)