[hta3] Chain of ESI Injection & Reflected XSS leading to Account Takeover on [βββ]
π https://hackerone.com/reports/1073780
πΉ Severity: High | π° 750 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #jr0ch17
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:44pm (UTC)
π https://hackerone.com/reports/1073780
πΉ Severity: High | π° 750 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #jr0ch17
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:44pm (UTC)
Local file read at https://ββββ/ [HtUS]
π https://hackerone.com/reports/1626210
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #sudi
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:51pm (UTC)
π https://hackerone.com/reports/1626210
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #sudi
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:51pm (UTC)
Broken access discloses users and PII at https://βββββββ [HtUS]
π https://hackerone.com/reports/1624374
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #g4mb4
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:53pm (UTC)
π https://hackerone.com/reports/1624374
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #g4mb4
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 1:53pm (UTC)
Found Origin IP's Lead To Access ββββ
π https://hackerone.com/reports/1556808
πΉ Severity: Low
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #ibrahim0936356
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 2:28pm (UTC)
π https://hackerone.com/reports/1556808
πΉ Severity: Low
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #ibrahim0936356
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 2:28pm (UTC)
Subdomain Takeover at https://ββ.get8x8.com/
π https://hackerone.com/reports/1697402
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #testingforbugs
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 3:05pm (UTC)
π https://hackerone.com/reports/1697402
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #testingforbugs
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 3:05pm (UTC)
SSRF to read AWS metaData at https://βββββ/ [HtUS]
π https://hackerone.com/reports/1624140
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #720922
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 3:12pm (UTC)
π https://hackerone.com/reports/1624140
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #720922
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 3:12pm (UTC)
π1
Authentication bypass leads to Information Disclosure at U.S Air Force "https://βββ"
π https://hackerone.com/reports/1690548
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #ludv1k
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:01pm (UTC)
π https://hackerone.com/reports/1690548
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #ludv1k
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:01pm (UTC)
Unauthenticated PII leak on verified/requested to be verified profiles on βββββββ/app/org/{id}/profile/{id}/version/{id} [HtUS]
π https://hackerone.com/reports/1627962
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #shreky
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:04pm (UTC)
π https://hackerone.com/reports/1627962
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #shreky
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:04pm (UTC)
.git folder exposed [HtUS]
π https://hackerone.com/reports/1624157
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #sudi
πΉ State: π€ Duplicate
πΉ Disclosed: October 14, 2022, 5:44pm (UTC)
π https://hackerone.com/reports/1624157
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #sudi
πΉ State: π€ Duplicate
πΉ Disclosed: October 14, 2022, 5:44pm (UTC)
Unauthenticated SQL Injection at βββββββββ [HtUS]
π https://hackerone.com/reports/1626226
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0xd0ff9
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:54pm (UTC)
π https://hackerone.com/reports/1626226
πΉ Severity: Critical | π° 1,000 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0xd0ff9
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 5:54pm (UTC)
Host Header Injection on https://βββ/ββββββββ/Account/ForgotPassword
π https://hackerone.com/reports/1679969
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x1int
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 6:03pm (UTC)
π https://hackerone.com/reports/1679969
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x1int
πΉ State: π’ Resolved
πΉ Disclosed: October 14, 2022, 6:03pm (UTC)
Otp bypass in verifying nin
π https://hackerone.com/reports/1314172
πΉ Severity: High
πΉ Reported To: MTN Group
πΉ Reported By: #mr_sparrow
πΉ State: π’ Resolved
πΉ Disclosed: October 17, 2022, 6:27am (UTC)
π https://hackerone.com/reports/1314172
πΉ Severity: High
πΉ Reported To: MTN Group
πΉ Reported By: #mr_sparrow
πΉ State: π’ Resolved
πΉ Disclosed: October 17, 2022, 6:27am (UTC)
XSS in www.shopify.com/markets?utm_source=
π https://hackerone.com/reports/1699762
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #noblesix
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 7:14am (UTC)
π https://hackerone.com/reports/1699762
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #noblesix
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 7:14am (UTC)
CVE-2017-5929: Hyperledger - Arbitrary Deserialization of Untrusted Data
π https://hackerone.com/reports/1739099
πΉ Severity: No Rating
πΉ Reported To: Hyperledger
πΉ Reported By: #mik-patient
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 3:36pm (UTC)
π https://hackerone.com/reports/1739099
πΉ Severity: No Rating
πΉ Reported To: Hyperledger
πΉ Reported By: #mik-patient
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 3:36pm (UTC)
TikTok Account Creation Date Information Disclosure
π https://hackerone.com/reports/1562020
πΉ Severity: Low | π° 100 USD
πΉ Reported To: TikTok
πΉ Reported By: #f15
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 8:50pm (UTC)
π https://hackerone.com/reports/1562020
πΉ Severity: Low | π° 100 USD
πΉ Reported To: TikTok
πΉ Reported By: #f15
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 8:50pm (UTC)
Access to private file's of helpdesk.
π https://hackerone.com/reports/804534
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:05pm (UTC)
π https://hackerone.com/reports/804534
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:05pm (UTC)
Sub-Dept User Can Add User's To Main Department.
π https://hackerone.com/reports/890209
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:08pm (UTC)
π https://hackerone.com/reports/890209
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:08pm (UTC)
Users Without Permission Can Download Restricted Files
π https://hackerone.com/reports/794904
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:10pm (UTC)
π https://hackerone.com/reports/794904
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Lark Technologies
πΉ Reported By: #imran_nisar
πΉ State: π’ Resolved
πΉ Disclosed: October 18, 2022, 9:10pm (UTC)
DOM XSS at `https://adobedocs.github.io/OAE_PartnerAPI/?configUrl={site}` due to outdated Swagger UI
π https://hackerone.com/reports/1736378
πΉ Severity: Medium
πΉ Reported To: Adobe
πΉ Reported By: #dreamer_eh
πΉ State: π’ Resolved
πΉ Disclosed: October 19, 2022, 12:07pm (UTC)
π https://hackerone.com/reports/1736378
πΉ Severity: Medium
πΉ Reported To: Adobe
πΉ Reported By: #dreamer_eh
πΉ State: π’ Resolved
πΉ Disclosed: October 19, 2022, 12:07pm (UTC)
IDOR able to buy a plan with lesser fee
π https://hackerone.com/reports/1679276
πΉ Severity: Medium
πΉ Reported To: Automattic
πΉ Reported By: #ug0x01
πΉ State: βͺοΈ Informative
πΉ Disclosed: October 19, 2022, 4:20pm (UTC)
π https://hackerone.com/reports/1679276
πΉ Severity: Medium
πΉ Reported To: Automattic
πΉ Reported By: #ug0x01
πΉ State: βͺοΈ Informative
πΉ Disclosed: October 19, 2022, 4:20pm (UTC)
Fully TaxJar account control and ability to disclose and modify business account settings Due to Broken Access Control in /current_user_data
π https://hackerone.com/reports/1677541
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Stripe
πΉ Reported By: #mr_asg
πΉ State: π’ Resolved
πΉ Disclosed: October 19, 2022, 6:36pm (UTC)
π https://hackerone.com/reports/1677541
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Stripe
πΉ Reported By: #mr_asg
πΉ State: π’ Resolved
πΉ Disclosed: October 19, 2022, 6:36pm (UTC)