Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Internal IP addresses range and AWS cluster region leaked in a Github repository

πŸ‘‰ https://hackerone.com/reports/877303

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Kubernetes
πŸ”Ή Reported By: #cyberhawksec
πŸ”Ή Disclosed: July 24, 2020, 12:43am (UTC)
No Rate Limiting On Phone Number Login Leads to Login Bypass

πŸ‘‰ https://hackerone.com/reports/903363

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Smule
πŸ”Ή Reported By: #done11
πŸ”Ή Disclosed: July 24, 2020, 2:19am (UTC)
DoS for client-go jsonpath func

πŸ‘‰ https://hackerone.com/reports/882923

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Kubernetes
πŸ”Ή Reported By: #lazydog
πŸ”Ή Disclosed: July 24, 2020, 3:46am (UTC)
Getting SmartDNS for free from - join.nordvpn.com

πŸ‘‰ https://hackerone.com/reports/925757

πŸ”Ή Severity: High
πŸ”Ή Reported To: NordVPN
πŸ”Ή Reported By: #salahhasoneh
πŸ”Ή Disclosed: July 24, 2020, 9:01am (UTC)
Business Logic Flaw - A non premium user can change/update retailers to get cashback on all the retailers associated with Curve

πŸ‘‰ https://hackerone.com/reports/672487

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Curve
πŸ”Ή Reported By: #praseudo7
πŸ”Ή Disclosed: July 24, 2020, 12:28pm (UTC)
Stored XSS at [ https://app.lemlist.com/campaigns/cam_QRS5caF2ca7MJtiLS/leads ] in " LINKEDIN URL" Field.

πŸ‘‰ https://hackerone.com/reports/932557

πŸ”Ή Severity: Low
πŸ”Ή Reported To: lemlist
πŸ”Ή Reported By: #try___for___impossible
πŸ”Ή Disclosed: July 24, 2020, 2:01pm (UTC)
Grammarly Keyboard for Android "Authorization Code with PKCE" flow implementation vulnerability that allows account takeover

πŸ‘‰ https://hackerone.com/reports/824931

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Grammarly
πŸ”Ή Reported By: #tomtenisse
πŸ”Ή Disclosed: July 24, 2020, 2:22pm (UTC)
CVE-2019-19935 - DOM based XSS in the froala editor

πŸ‘‰ https://hackerone.com/reports/938683

πŸ”Ή Severity: Low
πŸ”Ή Reported To: lemlist
πŸ”Ή Reported By: #chackal
πŸ”Ή Disclosed: July 24, 2020, 3:33pm (UTC)
SQL Injection or Denial of Service due to a Prototype Pollution

πŸ‘‰ https://hackerone.com/reports/869574

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #phra
πŸ”Ή Disclosed: July 24, 2020, 5:20pm (UTC)
SAML Response Reuse on hackerone.com/users/saml/auth

πŸ‘‰ https://hackerone.com/reports/888930

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #samtink
πŸ”Ή Disclosed: July 24, 2020, 6:51pm (UTC)
Denial of Service [Chrome]

πŸ‘‰ https://hackerone.com/reports/921286

πŸ”Ή Severity: Medium | πŸ’° 560 USD
πŸ”Ή Reported To: Twitter
πŸ”Ή Reported By: #cyanpiny
πŸ”Ή Disclosed: July 24, 2020, 8:00pm (UTC)
Untrusted users able to run pending migrations in production

πŸ‘‰ https://hackerone.com/reports/899069

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: #tenderlove
πŸ”Ή Disclosed: July 24, 2020, 8:07pm (UTC)
GraphQL field on Team node can be used to determine if External Program runs invite-only program

πŸ‘‰ https://hackerone.com/reports/877642

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #kunal94
πŸ”Ή Disclosed: July 25, 2020, 1:13am (UTC)
Contacts menu (not app) fails to restrict (to local groups) for contacts from federated servers

πŸ‘‰ https://hackerone.com/reports/895730

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #nursoda
πŸ”Ή Disclosed: July 25, 2020, 8:10am (UTC)
Improper validation of unicode characters#2

πŸ‘‰ https://hackerone.com/reports/279945

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: #code_monkey
πŸ”Ή Disclosed: July 26, 2020, 10:50am (UTC)
Open Github Repo Leaking WEBLATE SECRET KEY

πŸ‘‰ https://hackerone.com/reports/942146

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: #nafisaqil4
πŸ”Ή Disclosed: July 26, 2020, 11:24am (UTC)
IDOR with Geolocation data not stripped from images

πŸ‘‰ https://hackerone.com/reports/906907

πŸ”Ή Severity: High | πŸ’° 200 USD
πŸ”Ή Reported To: IRCCloud
πŸ”Ή Reported By: #do_some_hack
πŸ”Ή Disclosed: July 26, 2020, 3:36pm (UTC)
Account takeover w/o interaction for a user that doesn't have 2fa enabled via 2fa linking and improper auth at /api/2fa/verify

πŸ‘‰ https://hackerone.com/reports/810880

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Helium
πŸ”Ή Reported By: #w2w
πŸ”Ή Disclosed: July 26, 2020, 4:39pm (UTC)
Send arbitrary PUT requests when user clicks on a link

πŸ‘‰ https://hackerone.com/reports/824689

πŸ”Ή Severity: Medium | πŸ’° 3000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #yvvdwf
πŸ”Ή Disclosed: July 27, 2020, 8:44am (UTC)
πŸ“† July 31 - August 1, 2020

h@cktivitycon is a HackerOne hosted hacker conference built by the community for the community.

h@cktivitycon is a place for hackers to learn, share, and meet friends. Hear talks and panelists exploring offensive hacking techniques, recon skills, target selection and more.

πŸ—£ Speakers | ⏱ Schedule

πŸš€ Register now
Cross-Site WebSocket Hijacking Lead to Steal XSRF-TOKEN

πŸ‘‰ https://hackerone.com/reports/915541

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Stripo Inc
πŸ”Ή Reported By: #3x3s
πŸ”Ή Disclosed: July 27, 2020, 12:54pm (UTC)