Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler

πŸ‘‰ https://hackerone.com/reports/1081167

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #bored-engineer
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 7:34pm (UTC)
Disconnecting an external login provider does not revoke session

πŸ‘‰ https://hackerone.com/reports/1547684

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #attackerbhai
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 7:50pm (UTC)
Stored XSS in /admin/product and /admin/collections

πŸ‘‰ https://hackerone.com/reports/1147433

πŸ”Ή Severity: Medium | πŸ’° 5,300 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ashketchum
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 10:44pm (UTC)
Authentication bypass in https://nin.mtn.ng

πŸ‘‰ https://hackerone.com/reports/1747146

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #roland_hack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 1:00pm (UTC)
XSS in Acronis Cloud Manager Admin Portal

πŸ‘‰ https://hackerone.com/reports/1388788

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Acronis
πŸ”Ή Reported By: #mooimacow
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 7:48pm (UTC)
POST following PUT confusion

πŸ‘‰ https://hackerone.com/reports/1752146

πŸ”Ή Severity: Medium | πŸ’° 2,400 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #robbotic
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 9:03pm (UTC)
Exposed Cortex API at https://cortex-ingest.shopifycloud.com/

πŸ‘‰ https://hackerone.com/reports/1258871

πŸ”Ή Severity: Medium | πŸ’° 6,300 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ian
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 10:25pm (UTC)
πŸ‘1
CVE-2022-35260: .netrc parser out-of-bounds access

πŸ‘‰ https://hackerone.com/reports/1753224

πŸ”Ή Severity: Low | πŸ’° 480 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #kurohiro
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 3, 2022, 12:20am (UTC)
πŸ‘1
IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account

πŸ‘‰ https://hackerone.com/reports/1644436

πŸ”Ή Severity: No Rating | πŸ’° 1,000 USD
πŸ”Ή Reported To: EXNESS
πŸ”Ή Reported By: #ashwarya
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 5, 2022, 3:50pm (UTC)
πŸ‘9❀2
[Splatoon 3] Kick other players with NplnLogin message

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Nintendo
πŸ”Ή Reported By: alzxk11
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 2, 2026, 1:25am (UTC)

A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.

πŸ‘‰ Read full report
❀1
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed

πŸ”Ή Severity: None
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: abahack
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: July 3, 2026, 6:50pm (UTC)

πŸ‘‰ Read full report
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity

πŸ”Ή Severity: Medium | πŸ’° 287 USD
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Basecamp
πŸ”Ή Reported By: zerodaysec_xyz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 4, 2026, 11:05am (UTC)

A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session and…

πŸ‘‰ Read full report
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)

πŸ”Ή Severity: High
πŸ”Ή Weakness: OS Command Injection
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: kaporia
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 6, 2026, 5:48pm (UTC)

A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the host…

πŸ‘‰ Read full report
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Default Permissions
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 9, 2026, 3:31pm (UTC)

The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.

πŸ‘‰ Read full report
πŸ‘1
Unauthenticated Access to MMGIS Webhooks

πŸ”Ή Severity: High
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: oversudo
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 7, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated Disclosure of NASA Organizer Email Addresses via The Events Calendar REST API (CVE-2025-9808)

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: ARTanvir76
πŸ”Ή State: βšͺ️ Informational
πŸ”Ή Disclosed: July 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen Toast Can Be Hidden by Repeated Constraint Validation Popups

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: jodyritonga
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
πŸ‘‹ Hey hunters!

The channel just leveled up β€” disclosed reports now pull from two sources: HackerOne & Bugcrowd 🐞πŸ”₯

More features are on the way πŸš€ And you get a say β€” which platform should we plug in next? React to vote πŸ‘‡

πŸ”₯ β€” Immunefi (web3)
πŸ‘ β€” huntr (open source)
πŸ€” β€” something else (tell us in comments)
❀5πŸ”₯3πŸ‘2πŸ€”2
Unauthenticated Error-Based SQL Injection in HEASARC W3Browse w3hdprods.pl

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Anon0x0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 13, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server

πŸ”Ή Severity: High
πŸ”Ή Weakness: Missing Authorization
πŸ”Ή Reported To: SingleStore
πŸ”Ή Reported By: bisht-ji
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 13, 2026, 7:35pm (UTC)
🐞 Source: HackerOne

A security vulnerability was reported in SingleStore's self-managed database server where the SELECT...INTO OUTFILE command did not properly enforce the FILE WRITE privilege. This allowed any authenticated user, including those with only USAGE privileges, to write arbitrary files to the aggregator host at any path, written as the engine OS user. The vulnerability affected default-configuration self-managed…

πŸ‘‰ Read full report
πŸ‘1
One-Click Data Exfiltration via rovoChatPrompt URL Parameter (Confluence / Rovo)

πŸ”Ή Severity: High
πŸ”Ή Reported To: Atlassian
πŸ”Ή Reported By: loacker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report