XSS in Desktop Client via user status and information
π https://hackerone.com/reports/1707977
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #mikeisastar
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 3:44pm (UTC)
π https://hackerone.com/reports/1707977
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #mikeisastar
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 3:44pm (UTC)
XSS in Desktop Client in call notification popup
π https://hackerone.com/reports/1711847
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #mikeisastar
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 3:45pm (UTC)
π https://hackerone.com/reports/1711847
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #mikeisastar
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 3:45pm (UTC)
SSRF - pivoting in the private LAN
π https://hackerone.com/reports/1364797
πΉ Severity: Low
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 5:20pm (UTC)
π https://hackerone.com/reports/1364797
πΉ Severity: Low
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 5:20pm (UTC)
open redirect to a remote website which can phish users
π https://hackerone.com/reports/1397804
πΉ Severity: Medium
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 25, 2022, 6:08pm (UTC)
π https://hackerone.com/reports/1397804
πΉ Severity: Medium
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: βͺοΈ Informative
πΉ Disclosed: November 25, 2022, 6:08pm (UTC)
SSRF mitigation bypass using DNS Rebind attack
π https://hackerone.com/reports/1369312
πΉ Severity: Low
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 6:11pm (UTC)
π https://hackerone.com/reports/1369312
πΉ Severity: Low
πΉ Reported To: Concrete CMS
πΉ Reported By: #adrian_t
πΉ State: π’ Resolved
πΉ Disclosed: November 25, 2022, 6:11pm (UTC)
π1
Database resource exhaustion for logged-in users via sharee recommendations with circles
π https://hackerone.com/reports/1688199
πΉ Severity: Medium | π° 250 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #michag86
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 6:52am (UTC)
π https://hackerone.com/reports/1688199
πΉ Severity: Medium | π° 250 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #michag86
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 6:52am (UTC)
Profile of disabled user stays accessible
π https://hackerone.com/reports/1675014
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #mikaelgundersen
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 6:53am (UTC)
π https://hackerone.com/reports/1675014
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #mikaelgundersen
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 6:53am (UTC)
CVE-2022-32221: POST following PUT confusion
π https://hackerone.com/reports/1704017
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:02pm (UTC)
π https://hackerone.com/reports/1704017
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #robbotic
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:02pm (UTC)
CVE-2022-42915: HTTP proxy double-free
π https://hackerone.com/reports/1722065
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #bagder
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:04pm (UTC)
π https://hackerone.com/reports/1722065
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #bagder
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:04pm (UTC)
Exception logging in Sharepoint app reveals clear-text connection details
π https://hackerone.com/reports/1652903
πΉ Severity: Medium
πΉ Reported To: Nextcloud
πΉ Reported By: #kichernde_erbse
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:46pm (UTC)
π https://hackerone.com/reports/1652903
πΉ Severity: Medium
πΉ Reported To: Nextcloud
πΉ Reported By: #kichernde_erbse
πΉ State: π’ Resolved
πΉ Disclosed: November 26, 2022, 12:46pm (UTC)
Wordpress users Disclosure [ /wp-json/wp/v2/users/ ]
π https://hackerone.com/reports/1735586
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #shubham_srt
πΉ State: π’ Resolved
πΉ Disclosed: November 27, 2022, 3:25am (UTC)
π https://hackerone.com/reports/1735586
πΉ Severity: Critical
πΉ Reported To: MTN Group
πΉ Reported By: #shubham_srt
πΉ State: π’ Resolved
πΉ Disclosed: November 27, 2022, 3:25am (UTC)
potential denial of service attack via the locale parameter
π https://hackerone.com/reports/1746098
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #benjaoming_realone
πΉ State: π’ Resolved
πΉ Disclosed: November 28, 2022, 6:31pm (UTC)
π https://hackerone.com/reports/1746098
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #benjaoming_realone
πΉ State: π’ Resolved
πΉ Disclosed: November 28, 2022, 6:31pm (UTC)
I found some api keys in js files ,huge leak of token addresses and huge amount of js files are not forbidden
π https://hackerone.com/reports/1787121
πΉ Severity: No Rating
πΉ Reported To: AMBER AI
πΉ Reported By: #orange_h
πΉ State: π΄ N/A
πΉ Disclosed: November 29, 2022, 10:46am (UTC)
π https://hackerone.com/reports/1787121
πΉ Severity: No Rating
πΉ Reported To: AMBER AI
πΉ Reported By: #orange_h
πΉ State: π΄ N/A
πΉ Disclosed: November 29, 2022, 10:46am (UTC)
π€3π2
Stored XSS in Dovetale by application of creator
π https://hackerone.com/reports/1652046
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #kun_19
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 5:34pm (UTC)
π https://hackerone.com/reports/1652046
πΉ Severity: Medium | π° 1,600 USD
πΉ Reported To: Shopify
πΉ Reported By: #kun_19
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 5:34pm (UTC)
Any organization's assets pending review can be downloaded
π https://hackerone.com/reports/1787644
πΉ Severity: High
πΉ Reported To: HackerOne
πΉ Reported By: #jobert
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 6:36pm (UTC)
π https://hackerone.com/reports/1787644
πΉ Severity: High
πΉ Reported To: HackerOne
πΉ Reported By: #jobert
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 6:36pm (UTC)
Stored XSS Payload when sending videos
π https://hackerone.com/reports/1536046
πΉ Severity: Low | π° 500 USD
πΉ Reported To: TikTok
πΉ Reported By: #aidilarf_2000
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 9:30pm (UTC)
π https://hackerone.com/reports/1536046
πΉ Severity: Low | π° 500 USD
πΉ Reported To: TikTok
πΉ Reported By: #aidilarf_2000
πΉ State: π’ Resolved
πΉ Disclosed: November 29, 2022, 9:30pm (UTC)
If the website does not impose additional defense against CSRF attacks, failing to use the 'Lax' or 'Strict' values could increase the risk of exposur
π https://hackerone.com/reports/1707680
πΉ Severity: Low
πΉ Reported To: Yelp
πΉ Reported By: #shubhangirathore836
πΉ State: π΄ N/A
πΉ Disclosed: November 30, 2022, 3:15pm (UTC)
π https://hackerone.com/reports/1707680
πΉ Severity: Low
πΉ Reported To: Yelp
πΉ Reported By: #shubhangirathore836
πΉ State: π΄ N/A
πΉ Disclosed: November 30, 2022, 3:15pm (UTC)
Campaign Account Balance and History Disclosed in API Response
π https://hackerone.com/reports/1587374
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: LinkedIn
πΉ Reported By: #sachin_kumar_
πΉ State: π’ Resolved
πΉ Disclosed: November 30, 2022, 7:31pm (UTC)
π https://hackerone.com/reports/1587374
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: LinkedIn
πΉ Reported By: #sachin_kumar_
πΉ State: π’ Resolved
πΉ Disclosed: November 30, 2022, 7:31pm (UTC)
Double evaluation in .bash_prompt of dotfiles allows a malicious repository to execute arbitrary commands
π https://hackerone.com/reports/1785378
πΉ Severity: High | π° 300 USD
πΉ Reported To: Ian Dunn
πΉ Reported By: #ryotak
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 4:00am (UTC)
π https://hackerone.com/reports/1785378
πΉ Severity: High | π° 300 USD
πΉ Reported To: Ian Dunn
πΉ Reported By: #ryotak
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 4:00am (UTC)
π₯2
CVE-2022-45402: Apache Airflow: Open redirect during login
π https://hackerone.com/reports/1782514
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #bugra
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 9:41am (UTC)
π https://hackerone.com/reports/1782514
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #bugra
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 9:41am (UTC)
Calendar name length not validated before writing to database
π https://hackerone.com/reports/1596148
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #errorx404
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 9:49am (UTC)
π https://hackerone.com/reports/1596148
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #errorx404
πΉ State: π’ Resolved
πΉ Disclosed: December 1, 2022, 9:49am (UTC)