Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Spring Actuator endpoints publicly available, leading to account takeover

πŸ‘‰ https://hackerone.com/reports/862589

πŸ”Ή Severity: Critical | πŸ’° 5,000 USD
πŸ”Ή Reported To: LINE
πŸ”Ή Reported By: #kazan71p
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 4, 2020, 2:52am (UTC)
Stored XSS in blob viewer

πŸ‘‰ https://hackerone.com/reports/806571

πŸ”Ή Severity: Medium | πŸ’° 2,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #yvvdwf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 4, 2020, 9:46am (UTC)
Time-base SQL Injection in Search Users

πŸ‘‰ https://hackerone.com/reports/876800

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: concrete5
πŸ”Ή Reported By: #thiennv
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2020, 1:08am (UTC)
XSS in image metadata field

πŸ‘‰ https://hackerone.com/reports/896511

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #yzy9951
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2020, 7:04am (UTC)
Arbitrary code execution in desktop client via OpenSSL config

πŸ‘‰ https://hackerone.com/reports/622170

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #l00ph0le
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2020, 8:50am (UTC)
S3 bucket data at http://rockset-support.s3-us-west-2.amazonaws.com/ reveals user addresses based on latitudes and longitudes.

πŸ‘‰ https://hackerone.com/reports/947725

πŸ”Ή Severity: High
πŸ”Ή Reported To: Rockset
πŸ”Ή Reported By: #thatquasar
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2020, 2:38pm (UTC)
Send Phishing/Spam email from support@sameroom.io to any email address.

πŸ‘‰ https://hackerone.com/reports/840688

πŸ”Ή Severity: High
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #wisp
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 5, 2020, 10:34pm (UTC)
Spring Actuator endpoints publicly available and broken authentication

πŸ‘‰ https://hackerone.com/reports/838635

πŸ”Ή Severity: Critical | πŸ’° 12,500 USD
πŸ”Ή Reported To: LINE
πŸ”Ή Reported By: #kazan71p
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 6, 2020, 5:13am (UTC)
Memory Leak in OCUtil.dll library in Desktop client can lead to DoS

πŸ‘‰ https://hackerone.com/reports/588562

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #cwave
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 6, 2020, 1:56pm (UTC)
[wappalyzer] ReDoS allows an attacker to completely break Wappalyzer

πŸ‘‰ https://hackerone.com/reports/888030

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #vrechson
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 6, 2020, 10:56pm (UTC)
Lack of Input sanitization leads to database Character encoding configuration Disclosure

πŸ‘‰ https://hackerone.com/reports/866271

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Unikrn
πŸ”Ή Reported By: #l_user
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 8:48am (UTC)
Full Read SSRF on Gitlab's Internal Grafana

πŸ‘‰ https://hackerone.com/reports/878779

πŸ”Ή Severity: Critical | πŸ’° 12,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #rhynorater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 1:48pm (UTC)
Server-Side Request Forgery in "icons.bitwarden.net"

πŸ‘‰ https://hackerone.com/reports/913276

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Bitwarden
πŸ”Ή Reported By: #njgadhiya
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 2:39pm (UTC)
Blind stored XSS due to insecure contact form at https://www.topcoder.com leads to leakage of session token and other PII

πŸ‘‰ https://hackerone.com/reports/878145

πŸ”Ή Severity: High
πŸ”Ή Reported To: Topcoder
πŸ”Ή Reported By: #mase289
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 5:17pm (UTC)
Improper use of "path" parameter can be used to trick testers into leaking their Front-End PoC

πŸ‘‰ https://hackerone.com/reports/926221

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: BugPoC
πŸ”Ή Reported By: #acut3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 7:12pm (UTC)
Availing Zomato gold by using a random third-party `wallet_id`

πŸ‘‰ https://hackerone.com/reports/938021

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #pandaaaa
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 7:42pm (UTC)
Ability to manipulate price with a max threshold of `<1 Rupee` in support rider parameter

πŸ‘‰ https://hackerone.com/reports/927661

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #0xdexter
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 8, 2020, 7:36am (UTC)
Access control on https://eaccounting.stage.vismaonline.com/

πŸ‘‰ https://hackerone.com/reports/812143

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #brdoors3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 9, 2020, 7:57pm (UTC)
Solr Injection in `user_id` parameter at :/v2/leaderboard_v2.json

πŸ‘‰ https://hackerone.com/reports/952501

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 7:50am (UTC)
Unauthenticated users can access all food.grammarly.io user's data

πŸ‘‰ https://hackerone.com/reports/745495

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: Grammarly
πŸ”Ή Reported By: #cript0nauta
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 10:10am (UTC)
[www.zomato.com] Abusing LocalParams (city) to Inject SOLR query

πŸ‘‰ https://hackerone.com/reports/844428

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 1:23pm (UTC)