Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Pre-auth Denial-of-Service in Dovecot RPA implementation

πŸ‘‰ https://hackerone.com/reports/866605

πŸ”Ή Severity: Medium | πŸ’° 550 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #orange
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:43am (UTC)
Pre-auth buffer over-read in Dovecot NTLM implementation

πŸ‘‰ https://hackerone.com/reports/866597

πŸ”Ή Severity: Medium | πŸ’° 550 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #orange
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:43am (UTC)
SSRF in imgur video GIF conversion

πŸ‘‰ https://hackerone.com/reports/247680

πŸ”Ή Severity: High | πŸ’° 1,000 USD
πŸ”Ή Reported To: Imgur
πŸ”Ή Reported By: #justchillin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:15am (UTC)
Stored XSS at APM applications listing

πŸ‘‰ https://hackerone.com/reports/530511

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:45am (UTC)
Stored XSS firing if the error occurs when trying to delete the APM app

πŸ‘‰ https://hackerone.com/reports/530871

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:46am (UTC)
User can run monitors at private locations, which he has no access to

πŸ‘‰ https://hackerone.com/reports/681001

πŸ”Ή Severity: High | πŸ’° 3,000 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:52am (UTC)
Stored XSS at APM apps labels autocomplete dropdown (apps listing)

πŸ‘‰ https://hackerone.com/reports/534711

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:53am (UTC)
CSRF at acknowledging an incident

πŸ‘‰ https://hackerone.com/reports/512102

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:53am (UTC)
CSTI fix (#587829) bypass leading to stored XSS at plugins again

πŸ‘‰ https://hackerone.com/reports/629113

πŸ”Ή Severity: High | πŸ’° 1,000 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:57am (UTC)
CSTI at Plugin page leading to active stored XSS (Publisher name)

πŸ‘‰ https://hackerone.com/reports/587829

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:57am (UTC)
Stored XSS firing at the "Add chart to note" popup

πŸ‘‰ https://hackerone.com/reports/566400

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:58am (UTC)
Stored XSS at APM key transactions list

πŸ‘‰ https://hackerone.com/reports/567468

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:58am (UTC)
Stored XSS firing at transaction map (applicationName field)

πŸ‘‰ https://hackerone.com/reports/549084

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:58am (UTC)
Urgent! Stored XSS at plugin's violations leading to account takeover

πŸ‘‰ https://hackerone.com/reports/602527

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:59am (UTC)
Site-wide clickjacking at IE11

πŸ‘‰ https://hackerone.com/reports/614947

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:59am (UTC)
CSRF at adding new role (user-management.service.newrelic.com)

πŸ‘‰ https://hackerone.com/reports/504782

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:04am (UTC)
Stored XSS at Mobile (Versions tab)

πŸ‘‰ https://hackerone.com/reports/706533

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:04am (UTC)
Cross-account stored XSS at notes (through "swf" note parameter)

πŸ‘‰ https://hackerone.com/reports/710535

πŸ”Ή Severity: High | πŸ’° 2,000 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:05am (UTC)
Unsafe charts embedding implementation leads to cross-account stored XSS and SSRF

πŸ‘‰ https://hackerone.com/reports/708589

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:06am (UTC)
Passive stored XSS at Synthetics job result page (View resource)

πŸ‘‰ https://hackerone.com/reports/690536

πŸ”Ή Severity: Medium | πŸ’° 1,075 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:10am (UTC)
Stored XSS in notes (charts) because of insecure chart data JSON generation

πŸ‘‰ https://hackerone.com/reports/507132

πŸ”Ή Severity: High | πŸ’° 4,250 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:27pm (UTC)