Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties ๐Ÿ“ฃ

Rate๐Ÿ‘‡
https://cutt.ly/bugpoint_rate
Feedback๐Ÿ‘‡
https://cutt.ly/bugpoint_feedback

#๏ธโƒฃ bug bounty disclosed reports
#๏ธโƒฃ bug bounty write-ups
#๏ธโƒฃ bug bounty teleg
Download Telegram
Reflected XSS | https://โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ

๐Ÿ‘‰ https://hackerone.com/reports/1736433

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: U.S. Dept Of Defense
๐Ÿ”น Reported By: #x3ph_
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 18, 2022, 6:33pm (UTC)
Reflected XSS | https://โ–ˆโ–ˆโ–ˆโ–ˆ

๐Ÿ‘‰ https://hackerone.com/reports/1736432

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: U.S. Dept Of Defense
๐Ÿ”น Reported By: #x3ph_
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 18, 2022, 6:34pm (UTC)
IDOR on โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ [HtUS]

๐Ÿ‘‰ https://hackerone.com/reports/1627974

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: U.S. Dept Of Defense
๐Ÿ”น Reported By: #nightm4re
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 18, 2022, 6:36pm (UTC)
Open Redirect at โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ

๐Ÿ‘‰ https://hackerone.com/reports/1634105

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: U.S. Dept Of Defense
๐Ÿ”น Reported By: #angeltsvetkov
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 18, 2022, 6:37pm (UTC)
Reflected XSS in chatbot

๐Ÿ‘‰ https://hackerone.com/reports/1735622

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: MTN Group
๐Ÿ”น Reported By: #roland_hack
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 19, 2022, 3:56pm (UTC)
No rate limiting for Remove Account lead to huge Mass mailings

๐Ÿ‘‰ https://hackerone.com/reports/1723445

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: Weblate
๐Ÿ”น Reported By: #tanvir_0x
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 20, 2022, 9:08am (UTC)
Dependecy Confusion via Lookup Request Forwarding to PyPi.org

๐Ÿ‘‰ https://hackerone.com/reports/1681275

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: GitLab
๐Ÿ”น Reported By: #usd-responsible-disclosure
๐Ÿ”น State: โšช๏ธ Informative
๐Ÿ”น Disclosed: November 21, 2022, 3:49am (UTC)
Open redirect that can lead to malicious websites

๐Ÿ‘‰ https://hackerone.com/reports/1771749

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: AMBER AI
๐Ÿ”น Reported By: #mrdot404
๐Ÿ”น State: โšช๏ธ Informative
๐Ÿ”น Disclosed: November 21, 2022, 7:24am (UTC)
Support Portal Takeover via Leaked API KEY

๐Ÿ‘‰ https://hackerone.com/reports/1766228

๐Ÿ”น Severity: High | ๐Ÿ’ฐ 1,500 USD
๐Ÿ”น Reported To: AMBER AI
๐Ÿ”น Reported By: #khizer47
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 22, 2022, 9:55am (UTC)
DoS via Automatic Response Message

๐Ÿ‘‰ https://hackerone.com/reports/1680241

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 300 USD
๐Ÿ”น Reported To: Mattermost
๐Ÿ”น Reported By: #vultza
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 23, 2022, 2:55pm (UTC)
DoS via Playbook

๐Ÿ‘‰ https://hackerone.com/reports/1685979

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 300 USD
๐Ÿ”น Reported To: Mattermost
๐Ÿ”น Reported By: #vultza
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 23, 2022, 2:55pm (UTC)
RubyใฎCGIใƒฉใ‚คใƒ–ใƒฉใƒชใซHTTPใƒฌใ‚นใƒใƒณใ‚นๅˆ†ๅ‰ฒ๏ผˆHTTPใƒ˜ใƒƒใƒ€ใ‚คใƒณใ‚ธใ‚งใ‚ฏใ‚ทใƒงใƒณ๏ผ‰ใŒใ‚ใ‚Šใ€็ง˜ๅฏ†ๆƒ…ๅ ฑใŒๆผๆดฉใ™ใ‚‹

๐Ÿ‘‰ https://hackerone.com/reports/1204695

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Ruby
๐Ÿ”น Reported By: #htokumaru
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 24, 2022, 1:46am (UTC)
๐Ÿ‘1
CGI::Cookieใ‚ฏใƒฉใ‚นใซใŠใ‘ใ‚‹ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃไธŠๅฅฝใพใ—ใใชใ„ไป•ๆง˜ใŠใ‚ˆใณๅฎŸ่ฃ…

๐Ÿ‘‰ https://hackerone.com/reports/1204977

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Ruby
๐Ÿ”น Reported By: #htokumaru
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 24, 2022, 1:47am (UTC)
XSS in Desktop Client in the notifications

๐Ÿ‘‰ https://hackerone.com/reports/1668028

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 750 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 11:29am (UTC)
XSS in Desktop Client via user status and information

๐Ÿ‘‰ https://hackerone.com/reports/1707977

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 3:44pm (UTC)
XSS in Desktop Client in call notification popup

๐Ÿ‘‰ https://hackerone.com/reports/1711847

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 3:45pm (UTC)
SSRF - pivoting in the private LAN

๐Ÿ‘‰ https://hackerone.com/reports/1364797

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 5:20pm (UTC)
open redirect to a remote website which can phish users

๐Ÿ‘‰ https://hackerone.com/reports/1397804

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: โšช๏ธ Informative
๐Ÿ”น Disclosed: November 25, 2022, 6:08pm (UTC)
SSRF mitigation bypass using DNS Rebind attack

๐Ÿ‘‰ https://hackerone.com/reports/1369312

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 6:11pm (UTC)
๐Ÿ‘1
Database resource exhaustion for logged-in users via sharee recommendations with circles

๐Ÿ‘‰ https://hackerone.com/reports/1688199

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 250 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #michag86
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 6:52am (UTC)
Profile of disabled user stays accessible

๐Ÿ‘‰ https://hackerone.com/reports/1675014

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 100 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikaelgundersen
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 6:53am (UTC)