Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
LDAP injection vulnerability in Java

πŸ‘‰ https://hackerone.com/reports/956295

πŸ”Ή Severity: Critical | πŸ’° 2,500 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #grzegol
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 11, 2020, 6:20pm (UTC)
Improper access control allows sales only user to view bank balance of company accounts.

πŸ‘‰ https://hackerone.com/reports/906328

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #vapour
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 8:44am (UTC)
A sales only user can edit the purchase invoice drafts.

πŸ‘‰ https://hackerone.com/reports/918938

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #vapour
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 8:44am (UTC)
information disclosure via IDOR on "https://target.my.com/api/v2/coverage/segment.json?id={id}" endpoint

πŸ‘‰ https://hackerone.com/reports/763258

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #shuraros
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 9:53am (UTC)
tracker.my.com information disclosure via csrf bypass

πŸ‘‰ https://hackerone.com/reports/748538

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #shuraros
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 9:56am (UTC)
[c-api.city-mobil.ru] IDOR chat messages between driver and customer

πŸ‘‰ https://hackerone.com/reports/850637

πŸ”Ή Severity: No Rating | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #anyday
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 10:43am (UTC)
Vertical Privilege Escalation on {target.my.com}

πŸ‘‰ https://hackerone.com/reports/854973

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #dedsec69
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:44pm (UTC)
Subdomain takeover at msproject.geekbrains.ru

πŸ‘‰ https://hackerone.com/reports/922506

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #steal_wart
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:46pm (UTC)
Bypass OTP on contact back request at https://driver.city-mobil.ru/

πŸ‘‰ https://hackerone.com/reports/926228

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #nitin1205
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:48pm (UTC)
[performancemarketing.geekbrains.ru] Tilda Subdomain Takeover

πŸ‘‰ https://hackerone.com/reports/928602

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #xaleraf4ra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:49pm (UTC)
DOM based Cross-site Scripting

πŸ‘‰ https://hackerone.com/reports/954613

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: BugPoC
πŸ”Ή Reported By: #ivarsvids
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 2:58pm (UTC)
XSS Challenge #2 Solution

πŸ‘‰ https://hackerone.com/reports/953873

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: BugPoC
πŸ”Ή Reported By: #bad5ect0r
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 3:11pm (UTC)
Content Spoofing

πŸ‘‰ https://hackerone.com/reports/841630

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Acronis
πŸ”Ή Reported By: #full109tun
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 3:15pm (UTC)
Java: CWE-798 - Hardcoded AWS credentials

πŸ‘‰ https://hackerone.com/reports/956967

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #luchua
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 12, 2020, 4:54pm (UTC)
Pre-auth Denial-of-Service in Dovecot RPA implementation

πŸ‘‰ https://hackerone.com/reports/866605

πŸ”Ή Severity: Medium | πŸ’° 550 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #orange
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:43am (UTC)
Pre-auth buffer over-read in Dovecot NTLM implementation

πŸ‘‰ https://hackerone.com/reports/866597

πŸ”Ή Severity: Medium | πŸ’° 550 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #orange
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:43am (UTC)
SSRF in imgur video GIF conversion

πŸ‘‰ https://hackerone.com/reports/247680

πŸ”Ή Severity: High | πŸ’° 1,000 USD
πŸ”Ή Reported To: Imgur
πŸ”Ή Reported By: #justchillin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:15am (UTC)
Stored XSS at APM applications listing

πŸ‘‰ https://hackerone.com/reports/530511

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:45am (UTC)
Stored XSS firing if the error occurs when trying to delete the APM app

πŸ‘‰ https://hackerone.com/reports/530871

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:46am (UTC)
User can run monitors at private locations, which he has no access to

πŸ‘‰ https://hackerone.com/reports/681001

πŸ”Ή Severity: High | πŸ’° 3,000 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:52am (UTC)
Stored XSS at APM apps labels autocomplete dropdown (apps listing)

πŸ‘‰ https://hackerone.com/reports/534711

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:53am (UTC)