Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Availing Zomato gold by using a random third-party `wallet_id`

πŸ‘‰ https://hackerone.com/reports/938021

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #pandaaaa
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 7, 2020, 7:42pm (UTC)
Ability to manipulate price with a max threshold of `<1 Rupee` in support rider parameter

πŸ‘‰ https://hackerone.com/reports/927661

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #0xdexter
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 8, 2020, 7:36am (UTC)
Access control on https://eaccounting.stage.vismaonline.com/

πŸ‘‰ https://hackerone.com/reports/812143

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #brdoors3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 9, 2020, 7:57pm (UTC)
Solr Injection in `user_id` parameter at :/v2/leaderboard_v2.json

πŸ‘‰ https://hackerone.com/reports/952501

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 7:50am (UTC)
Unauthenticated users can access all food.grammarly.io user's data

πŸ‘‰ https://hackerone.com/reports/745495

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: Grammarly
πŸ”Ή Reported By: #cript0nauta
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 10:10am (UTC)
[www.zomato.com] Abusing LocalParams (city) to Inject SOLR query

πŸ‘‰ https://hackerone.com/reports/844428

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 1:23pm (UTC)
[www.zomato.com] Blind SQL Injection in /php/geto2banner

πŸ‘‰ https://hackerone.com/reports/838855

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 1:27pm (UTC)
[www.zomato.com] Blind SQL Injection in /php/widgets_handler.php

πŸ‘‰ https://hackerone.com/reports/836079

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 10, 2020, 1:38pm (UTC)
[api.zomato.com] Abusing LocalParams (city_id) to Inject SOLR query

πŸ‘‰ https://hackerone.com/reports/953203

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #zzzhacker13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2020, 8:34am (UTC)
Missing authorization allows sales only user to record payment.

πŸ‘‰ https://hackerone.com/reports/919008

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #vapour
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2020, 9:46am (UTC)
Lack of Password Confirmation for Account Deletion

πŸ‘‰ https://hackerone.com/reports/950471

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Zomato
πŸ”Ή Reported By: #cybrot
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 11, 2020, 12:22pm (UTC)
Golang : Improvements to Golang SSRF query

πŸ‘‰ https://hackerone.com/reports/956296

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #porcupineyhairs
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2020, 6:20pm (UTC)
LDAP injection vulnerability in Java

πŸ‘‰ https://hackerone.com/reports/956295

πŸ”Ή Severity: Critical | πŸ’° 2,500 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #grzegol
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2020, 6:20pm (UTC)
Improper access control allows sales only user to view bank balance of company accounts.

πŸ‘‰ https://hackerone.com/reports/906328

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #vapour
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 8:44am (UTC)
A sales only user can edit the purchase invoice drafts.

πŸ‘‰ https://hackerone.com/reports/918938

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #vapour
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 8:44am (UTC)
information disclosure via IDOR on "https://target.my.com/api/v2/coverage/segment.json?id={id}" endpoint

πŸ‘‰ https://hackerone.com/reports/763258

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #shuraros
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 9:53am (UTC)
tracker.my.com information disclosure via csrf bypass

πŸ‘‰ https://hackerone.com/reports/748538

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #shuraros
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 9:56am (UTC)
[c-api.city-mobil.ru] IDOR chat messages between driver and customer

πŸ‘‰ https://hackerone.com/reports/850637

πŸ”Ή Severity: No Rating | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #anyday
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 10:43am (UTC)
Vertical Privilege Escalation on {target.my.com}

πŸ‘‰ https://hackerone.com/reports/854973

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #dedsec69
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:44pm (UTC)
Subdomain takeover at msproject.geekbrains.ru

πŸ‘‰ https://hackerone.com/reports/922506

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #steal_wart
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:46pm (UTC)
Bypass OTP on contact back request at https://driver.city-mobil.ru/

πŸ‘‰ https://hackerone.com/reports/926228

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #nitin1205
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:48pm (UTC)