Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
DOM-Based XSS in tumblr.com

πŸ‘‰ https://hackerone.com/reports/882546

πŸ”Ή Severity: Medium | πŸ’° 350 USD
πŸ”Ή Reported To: Automattic
πŸ”Ή Reported By: #keer0k
πŸ”Ή Disclosed: July 27, 2020, 3:24pm (UTC)
JDBC credentials leaked via github

πŸ‘‰ https://hackerone.com/reports/935573

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #walidhossain
πŸ”Ή Disclosed: July 27, 2020, 4:44pm (UTC)
IDOR: Adding Contacts to Other User Groups

πŸ‘‰ https://hackerone.com/reports/879960

πŸ”Ή Severity: Low
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #ameyanekar
πŸ”Ή Disclosed: July 27, 2020, 4:50pm (UTC)
Python : Add query to detect Server Side Template Injection

πŸ‘‰ https://hackerone.com/reports/944359

πŸ”Ή Severity: High | πŸ’° 2300 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #porcupineyhairs
πŸ”Ή Disclosed: July 27, 2020, 9:45pm (UTC)
Wordpress Users Disclosure (/wp-json/wp/v2/users/) on data.gov

πŸ‘‰ https://hackerone.com/reports/942481

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: TTS Bug Bounty
πŸ”Ή Reported By: #nagli
πŸ”Ή Disclosed: July 28, 2020, 12:12am (UTC)
Stored XSS In mlbootcamp.ru

πŸ‘‰ https://hackerone.com/reports/820217

πŸ”Ή Severity: High
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #sniper302
πŸ”Ή Disclosed: July 28, 2020, 8:28am (UTC)
Content injection on shared event (calendar.mail.ru)

πŸ‘‰ https://hackerone.com/reports/847473

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #urban_tramp
πŸ”Ή Disclosed: July 28, 2020, 8:31am (UTC)
Blindy Replace User's Session with Attacker's Session

πŸ‘‰ https://hackerone.com/reports/892986

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #sayaanalam
πŸ”Ή Disclosed: July 28, 2020, 8:37am (UTC)
HTML/iframe/XSS injection on https://www.ucs.ru/online/shelter/settings/check/

πŸ‘‰ https://hackerone.com/reports/907867

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #hunter_py
πŸ”Ή Disclosed: July 28, 2020, 8:41am (UTC)
Test-scripts for postgis in mason-repository using unsafe unzip of content from unclaimed bucket creates potential RCE-issues

πŸ‘‰ https://hackerone.com/reports/329689

πŸ”Ή Severity: Critical | πŸ’° 12500 USD
πŸ”Ή Reported To: Mapbox
πŸ”Ή Reported By: #fransrosen
πŸ”Ή Disclosed: July 28, 2020, 7:37pm (UTC)
Singapore - Account Takeover via IDOR

πŸ‘‰ https://hackerone.com/reports/876300

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Starbucks
πŸ”Ή Reported By: #ko2sec
πŸ”Ή Disclosed: July 28, 2020, 7:44pm (UTC)
SQL injection in Razer Gold List Admin at /lists/index.php via the `list[]` parameter.

πŸ‘‰ https://hackerone.com/reports/824307

πŸ”Ή Severity: Critical | πŸ’° 2000 USD
πŸ”Ή Reported To: Razer
πŸ”Ή Reported By: #stealthy
πŸ”Ή Disclosed: July 28, 2020, 9:59pm (UTC)
User Access Control Bypass Via Razer elevated service ( RzKLService.exe ) which loads exe in misconfigured way.

πŸ‘‰ https://hackerone.com/reports/769684

πŸ”Ή Severity: High | πŸ’° 750 USD
πŸ”Ή Reported To: Razer
πŸ”Ή Reported By: #dredd_589
πŸ”Ή Disclosed: July 28, 2020, 10:01pm (UTC)
Missing rate limit in signup Form

πŸ‘‰ https://hackerone.com/reports/905692

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Courier
πŸ”Ή Reported By: #ahmed_almalky
πŸ”Ή Disclosed: July 28, 2020, 10:51pm (UTC)
"πŸ˜‚" + Unauthenticated Stored XSS in API at https://api.my.games/comments/v1/comments/update/

πŸ‘‰ https://hackerone.com/reports/853637

πŸ”Ή Severity: High
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #samet
πŸ”Ή Disclosed: July 28, 2020, 8:34am (UTC)
Possible denial of service when entering a loooong password

πŸ‘‰ https://hackerone.com/reports/840598

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #xcheater
πŸ”Ή Disclosed: July 29, 2020, 10:30am (UTC)
Fastify uses allErrors: true ajv configuration by default which is susceptible to DoS

πŸ‘‰ https://hackerone.com/reports/903521

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή Disclosed: July 29, 2020, 12:53pm (UTC)
Stealing the ip addres from users

πŸ‘‰ https://hackerone.com/reports/672499

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Vanilla
πŸ”Ή Reported By: #minoto
πŸ”Ή Disclosed: July 29, 2020, 4:13pm (UTC)
SQL injection (stacked queries) in the export to Excel functionality on Vidyo Server

πŸ‘‰ https://hackerone.com/reports/922567

πŸ”Ή Severity: High
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #b1ackgamba
πŸ”Ή State: Resolved
πŸ”Ή Disclosed: July 29, 2020, 5:07pm (UTC)
Stored XSS in my staff name fired in another your internal panel

πŸ‘‰ https://hackerone.com/reports/946053

πŸ”Ή Severity: High | πŸ’° 5,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #cyber__sec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2020, 10:06pm (UTC)
Bypass Too Many Requests Sign Up

πŸ‘‰ https://hackerone.com/reports/947349

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Courier
πŸ”Ή Reported By: #ni4hadpd
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: July 30, 2020, 6:52am (UTC)