Path traversal in filename in LINE Mac client
π https://hackerone.com/reports/727727
πΉ Severity: High | π° 2,785 USD
πΉ Reported To: LINE
πΉ Reported By: #hackerontwowheels
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 9:32am (UTC)
π https://hackerone.com/reports/727727
πΉ Severity: High | π° 2,785 USD
πΉ Reported To: LINE
πΉ Reported By: #hackerontwowheels
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 9:32am (UTC)
Reverse Tabnabbing in printing source document images
π https://hackerone.com/reports/911123
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Visma Public
πΉ Reported By: #artebels
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 12:40pm (UTC)
π https://hackerone.com/reports/911123
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Visma Public
πΉ Reported By: #artebels
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 12:40pm (UTC)
[is-my-json-valid] ReDoS via 'style' format
π https://hackerone.com/reports/909757
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 5:13pm (UTC)
π https://hackerone.com/reports/909757
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 5:13pm (UTC)
Arbitrary code execution via untrusted schemas in is-my-json-valid
π https://hackerone.com/reports/894308
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 5:14pm (UTC)
π https://hackerone.com/reports/894308
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 5:14pm (UTC)
Awesome XSS in Google docs via postMessage()
π¬ https://www.youtube.com/watch?v=aCexqB9qi70
πΉ Severity: Medium | π° 4,133.70 USD
πΉ Reported To: Google
πΉ Reported By: #nikolay
πΉ State: π’ Resolved
π¬ https://www.youtube.com/watch?v=aCexqB9qi70
πΉ Severity: Medium | π° 4,133.70 USD
πΉ Reported To: Google
πΉ Reported By: #nikolay
πΉ State: π’ Resolved
XSS on Videos IA
π https://hackerone.com/reports/910427
πΉ Severity: Medium
πΉ Reported To: DuckDuckGo
πΉ Reported By: #capuzsec
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 7:39pm (UTC)
π https://hackerone.com/reports/910427
πΉ Severity: Medium
πΉ Reported To: DuckDuckGo
πΉ Reported By: #capuzsec
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2020, 7:39pm (UTC)
curl overwrites local file with -J option if file non-readable, but file writable.
π https://hackerone.com/reports/926638
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #brumbrum
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 1, 2020, 4:46pm (UTC)
π https://hackerone.com/reports/926638
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #brumbrum
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 1, 2020, 4:46pm (UTC)
Get-based SSRF limited to HTTP protocol on https://resizer.line-apps.com/form
π https://hackerone.com/reports/707014
πΉ Severity: Medium | π° 1,350 USD
πΉ Reported To: LINE
πΉ Reported By: #ledz1996
πΉ State: π’ Resolved
πΉ Disclosed: August 2, 2020, 7:10am (UTC)
π https://hackerone.com/reports/707014
πΉ Severity: Medium | π° 1,350 USD
πΉ Reported To: LINE
πΉ Reported By: #ledz1996
πΉ State: π’ Resolved
πΉ Disclosed: August 2, 2020, 7:10am (UTC)
Facebook - Reputation Sync For #267890541047618
π https://hackerone.com/reports/896019
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Facebook
πΉ Reported By: #yashrs
πΉ State: π’ Resolved
πΉ Disclosed: August 2, 2020, 9:30am (UTC)
π https://hackerone.com/reports/896019
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Facebook
πΉ Reported By: #yashrs
πΉ State: π’ Resolved
πΉ Disclosed: August 2, 2020, 9:30am (UTC)
Anonymous file drop page ignores user profile visibility restrictions
π https://hackerone.com/reports/752353
πΉ Severity: No Rating
πΉ Reported To: Nextcloud
πΉ Reported By: #pshknst
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 8:27am (UTC)
π https://hackerone.com/reports/752353
πΉ Severity: No Rating
πΉ Reported To: Nextcloud
πΉ Reported By: #pshknst
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 8:27am (UTC)
relap.io IDOR
π https://hackerone.com/reports/749887
πΉ Severity: Low | π° 750 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #shuraros
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 9:39am (UTC)
π https://hackerone.com/reports/749887
πΉ Severity: Low | π° 750 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #shuraros
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 9:39am (UTC)
Account takeover through password reset in cups.mail.ru
π https://hackerone.com/reports/843160
πΉ Severity: High | π° 1,500 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #weev3kyaw
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 9:53am (UTC)
π https://hackerone.com/reports/843160
πΉ Severity: High | π° 1,500 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #weev3kyaw
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 9:53am (UTC)
Reflected XSS in "keywords" parameter at "https://sbermarket.ru/metro/search"
π https://hackerone.com/reports/898344
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #mehulpanchal007
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:05am (UTC)
π https://hackerone.com/reports/898344
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #mehulpanchal007
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:05am (UTC)
xss on [storehouse5.ucs.ru]
π https://hackerone.com/reports/900573
πΉ Severity: Low
πΉ Reported To: Mail.ru
πΉ Reported By: #pisarenko
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:09am (UTC)
π https://hackerone.com/reports/900573
πΉ Severity: Low
πΉ Reported To: Mail.ru
πΉ Reported By: #pisarenko
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:09am (UTC)
xss while uploading a file
π https://hackerone.com/reports/915346
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #aslanemre
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:10am (UTC)
π https://hackerone.com/reports/915346
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #aslanemre
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:10am (UTC)
Open Redirect at "city-mobil.ru"
π https://hackerone.com/reports/919241
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #kursadalsan
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:12am (UTC)
π https://hackerone.com/reports/919241
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #kursadalsan
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:12am (UTC)
Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API
π https://hackerone.com/reports/836081
πΉ Severity: High | π° 4,750 USD
πΉ Reported To: LINE
πΉ Reported By: #j0eii
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:48am (UTC)
π https://hackerone.com/reports/836081
πΉ Severity: High | π° 4,750 USD
πΉ Reported To: LINE
πΉ Reported By: #j0eii
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 10:48am (UTC)
Unrestricted file upload leads to Stored XSS
π https://hackerone.com/reports/880099
πΉ Severity: Medium | π° 1,500 USD
πΉ Reported To: GitLab
πΉ Reported By: #semsem123
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 12:26pm (UTC)
π https://hackerone.com/reports/880099
πΉ Severity: Medium | π° 1,500 USD
πΉ Reported To: GitLab
πΉ Reported By: #semsem123
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2020, 12:26pm (UTC)
Private list members disclosure via GraphQL
π https://hackerone.com/reports/885539
πΉ Severity: Low | π° 2,940 USD
πΉ Reported To: Twitter
πΉ Reported By: #ryotak
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 1:25am (UTC)
π https://hackerone.com/reports/885539
πΉ Severity: Low | π° 2,940 USD
πΉ Reported To: Twitter
πΉ Reported By: #ryotak
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 1:25am (UTC)
Spring Actuator endpoints publicly available, leading to account takeover
π https://hackerone.com/reports/862589
πΉ Severity: Critical | π° 5,000 USD
πΉ Reported To: LINE
πΉ Reported By: #kazan71p
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 2:52am (UTC)
π https://hackerone.com/reports/862589
πΉ Severity: Critical | π° 5,000 USD
πΉ Reported To: LINE
πΉ Reported By: #kazan71p
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 2:52am (UTC)
Stored XSS in blob viewer
π https://hackerone.com/reports/806571
πΉ Severity: Medium | π° 2,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 9:46am (UTC)
π https://hackerone.com/reports/806571
πΉ Severity: Medium | π° 2,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #yvvdwf
πΉ State: π’ Resolved
πΉ Disclosed: August 4, 2020, 9:46am (UTC)