Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
SQL injection (stacked queries) in the export to Excel functionality on Vidyo Server

πŸ‘‰ https://hackerone.com/reports/922567

πŸ”Ή Severity: High
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #b1ackgamba
πŸ”Ή State: Resolved
πŸ”Ή Disclosed: July 29, 2020, 5:07pm (UTC)
Stored XSS in my staff name fired in another your internal panel

πŸ‘‰ https://hackerone.com/reports/946053

πŸ”Ή Severity: High | πŸ’° 5,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #cyber__sec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 29, 2020, 10:06pm (UTC)
Bypass Too Many Requests Sign Up

πŸ‘‰ https://hackerone.com/reports/947349

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Courier
πŸ”Ή Reported By: #ni4hadpd
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: July 30, 2020, 6:52am (UTC)
SMTP Header Injection at http://abonement.ucs.ru

πŸ‘‰ https://hackerone.com/reports/901956

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #killinem_sec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 9:30am (UTC)
Stored XSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆhelpdesk

πŸ‘‰ https://hackerone.com/reports/901799

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #atbabers
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:45pm (UTC)
HTML Injection leads to XSS onβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/874228

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #lemonoftroy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:46pm (UTC)
RCE (Remote code execution) in one of DoD's websites

πŸ‘‰ https://hackerone.com/reports/874924

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #ilyass01
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:47pm (UTC)
PulseSSL VPN Site with Compromised Creds @ β–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/854049

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #r00tpgp
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:48pm (UTC)
Exposed Docker Registry at https://β–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/924487

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #chron0x
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:51pm (UTC)
Reflected XSS on https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/

πŸ‘‰ https://hackerone.com/reports/804364

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #the_unlucky_guy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:53pm (UTC)
Reflected XSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ page

πŸ‘‰ https://hackerone.com/reports/915573

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #scraps
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 5:54pm (UTC)
ajaxgetachievementsforgame is not guarded for unreleased apps

πŸ‘‰ https://hackerone.com/reports/835087

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: Valve
πŸ”Ή Reported By: #jameslll
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 30, 2020, 8:38pm (UTC)
Stored self XSS at auto.mail.ru using add_review functionality

πŸ‘‰ https://hackerone.com/reports/914286

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #avolume
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 7:17am (UTC)
Sidekiq Dashboard Publicly accessible at http://shopper.staging.instamart.ru/sidekiq/

πŸ‘‰ https://hackerone.com/reports/890513

πŸ”Ή Severity: Medium | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #sudi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 7:19am (UTC)
Path traversal in filename in LINE Mac client

πŸ‘‰ https://hackerone.com/reports/727727

πŸ”Ή Severity: High | πŸ’° 2,785 USD
πŸ”Ή Reported To: LINE
πŸ”Ή Reported By: #hackerontwowheels
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 9:32am (UTC)
Reverse Tabnabbing in printing source document images

πŸ‘‰ https://hackerone.com/reports/911123

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #artebels
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 12:40pm (UTC)
[is-my-json-valid] ReDoS via 'style' format

πŸ‘‰ https://hackerone.com/reports/909757

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 5:13pm (UTC)
Arbitrary code execution via untrusted schemas in is-my-json-valid

πŸ‘‰ https://hackerone.com/reports/894308

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 5:14pm (UTC)
Awesome XSS in Google docs via postMessage()

🎬 https://www.youtube.com/watch?v=aCexqB9qi70

πŸ”Ή Severity: Medium | πŸ’° 4,133.70 USD
πŸ”Ή Reported To: Google
πŸ”Ή Reported By: #nikolay
πŸ”Ή State: 🟒 Resolved
XSS on Videos IA

πŸ‘‰ https://hackerone.com/reports/910427

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: DuckDuckGo
πŸ”Ή Reported By: #capuzsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 31, 2020, 7:39pm (UTC)
curl overwrites local file with -J option if file non-readable, but file writable.

πŸ‘‰ https://hackerone.com/reports/926638

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: #brumbrum
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 1, 2020, 4:46pm (UTC)