Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Stored XSS firing at transaction map (applicationName field)

πŸ‘‰ https://hackerone.com/reports/549084

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:58am (UTC)
Urgent! Stored XSS at plugin's violations leading to account takeover

πŸ‘‰ https://hackerone.com/reports/602527

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:59am (UTC)
Site-wide clickjacking at IE11

πŸ‘‰ https://hackerone.com/reports/614947

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 10:59am (UTC)
CSRF at adding new role (user-management.service.newrelic.com)

πŸ‘‰ https://hackerone.com/reports/504782

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:04am (UTC)
Stored XSS at Mobile (Versions tab)

πŸ‘‰ https://hackerone.com/reports/706533

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:04am (UTC)
Cross-account stored XSS at notes (through "swf" note parameter)

πŸ‘‰ https://hackerone.com/reports/710535

πŸ”Ή Severity: High | πŸ’° 2,000 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:05am (UTC)
Unsafe charts embedding implementation leads to cross-account stored XSS and SSRF

πŸ‘‰ https://hackerone.com/reports/708589

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:06am (UTC)
Passive stored XSS at Synthetics job result page (View resource)

πŸ‘‰ https://hackerone.com/reports/690536

πŸ”Ή Severity: Medium | πŸ’° 1,075 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 11:10am (UTC)
Stored XSS in notes (charts) because of insecure chart data JSON generation

πŸ‘‰ https://hackerone.com/reports/507132

πŸ”Ή Severity: High | πŸ’° 4,250 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:27pm (UTC)
NR-wide cross account access through misconfigured CORS-policy of multiple endpoints

πŸ‘‰ https://hackerone.com/reports/751699

πŸ”Ή Severity: High | πŸ’° 3,125 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:30pm (UTC)
Disclosure of locally served nerdpacks due to nr-local.net CORS policy misconfiguration

πŸ‘‰ https://hackerone.com/reports/746786

πŸ”Ή Severity: Low | πŸ’° 625 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:31pm (UTC)
Stored admin-to-owner XSS at infrastructure alerts runbook URL leading to account takeover by malicious admin

πŸ‘‰ https://hackerone.com/reports/605845

πŸ”Ή Severity: Medium | πŸ’° 1,337 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:32pm (UTC)
Stored XSS on recruit.innogames.de

πŸ‘‰ https://hackerone.com/reports/917250

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: InnoGames
πŸ”Ή Reported By: #aeswagyewgyes
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:42pm (UTC)
Ability to run monitors' jobs of other accounts and to read these jobs content (including the secure credentials values)

πŸ‘‰ https://hackerone.com/reports/787886

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:45pm (UTC)
Cross-account stored XSS at embedded charts

πŸ‘‰ https://hackerone.com/reports/709883

πŸ”Ή Severity: High | πŸ’° 3,625 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:47pm (UTC)
Stored XSS at APM transaction map (transactionName field)

πŸ‘‰ https://hackerone.com/reports/667770

πŸ”Ή Severity: Medium | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 1:48pm (UTC)
One Click Remote Code Injection - *.blog.newrelic.com

πŸ‘‰ https://hackerone.com/reports/941421

πŸ”Ή Severity: Medium | πŸ’° 506 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #arsene_lupin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:14pm (UTC)
Secure credentials values disclosure to regular users due to access control issue in monitor creating function

πŸ‘‰ https://hackerone.com/reports/788499

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:19pm (UTC)
Attacker can create new account inside any partnership with no approve from the Partnership owner

πŸ‘‰ https://hackerone.com/reports/786109

πŸ”Ή Severity: Medium | πŸ’° 695 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:26pm (UTC)
Stored XSS at Synthetics private locations (planted through location label or description)

πŸ‘‰ https://hackerone.com/reports/680240

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:29pm (UTC)
Restricted user can manage the NerdGraph entities' tags

πŸ‘‰ https://hackerone.com/reports/757957

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:30pm (UTC)