Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Ability to buy PRO subscriptions by arbitrary reduced prices

πŸ‘‰ https://hackerone.com/reports/783688

πŸ”Ή Severity: Low | πŸ’° 203 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:37pm (UTC)
Account owner/admin can't actually delete personal users' API keys

πŸ‘‰ https://hackerone.com/reports/782703

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:38pm (UTC)
Restricted user can update Apdex target for applications by leveraging the GraphQL mutation

πŸ‘‰ https://hackerone.com/reports/776449

πŸ”Ή Severity: Medium | πŸ’° 626 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:39pm (UTC)
Restricted user can remove NerdStorage documents/collections scoped to ACCOUNT or ENTITY

πŸ‘‰ https://hackerone.com/reports/766145

πŸ”Ή Severity: Medium | πŸ’° 600 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 3:40pm (UTC)
Restricted user can add and delete tags of APM key transactions

πŸ‘‰ https://hackerone.com/reports/638685

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 4:39pm (UTC)
IDOR allows accounts to view full name of other accounts based on email through share notes feature

πŸ‘‰ https://hackerone.com/reports/476958

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 4:40pm (UTC)
Bypass of #447975 - view mobile application token though "Application Information" sidebar on Installation page

πŸ‘‰ https://hackerone.com/reports/479139

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 4:40pm (UTC)
https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability

πŸ‘‰ https://hackerone.com/reports/940384

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #they
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:08pm (UTC)
Path traversal on https://β–ˆβ–ˆβ–ˆ allows arbitrary file read (CVE-2020-3452)

πŸ‘‰ https://hackerone.com/reports/936399

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #un4gi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:09pm (UTC)
Remote Code Execution via CVE-2019-18935

πŸ‘‰ https://hackerone.com/reports/913695

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #un4gi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:11pm (UTC)
Stored XSS Via NRQL chartbuilder JSON view

πŸ‘‰ https://hackerone.com/reports/634692

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 13, 2020, 6:56pm (UTC)
Missing memory corruption protection on Windows release built

πŸ‘‰ https://hackerone.com/reports/380102

πŸ”Ή Severity: Medium | πŸ’° 50 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #secconsult
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 6:21am (UTC)
Default Creds Spring Boot Admin

πŸ‘‰ https://hackerone.com/reports/954818

πŸ”Ή Severity: High
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #testingforbugs
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 5:01pm (UTC)
Arbitrary code execution via untrusted schemas in ajv

πŸ‘‰ https://hackerone.com/reports/897974

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 5:21pm (UTC)
Denial-of- service By Cache Poisoning The Cross-Origin Resource Sharing Misconfiguration Allow Origin Header

πŸ‘‰ https://hackerone.com/reports/921704

πŸ”Ή Severity: Medium | πŸ’° 200 USD
πŸ”Ή Reported To: Automattic
πŸ”Ή Reported By: #hannanhaseeb
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 7:53pm (UTC)
HTML injection in email content

πŸ‘‰ https://hackerone.com/reports/786976

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Bitwala
πŸ”Ή Reported By: #lamscun
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 8:01pm (UTC)
SVG file upload leads to XML injection

πŸ‘‰ https://hackerone.com/reports/845832

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Topcoder
πŸ”Ή Reported By: #tushr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 14, 2020, 9:43pm (UTC)
Solution for XSS challenge calc.buggywebsite.com

πŸ‘‰ https://hackerone.com/reports/954249

πŸ”Ή Severity: High
πŸ”Ή Reported To: BugPoC
πŸ”Ή Reported By: #d1r3wolf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 15, 2020, 6:32pm (UTC)
Unrestricted File Upload in Chat Window

πŸ‘‰ https://hackerone.com/reports/925513

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: OWOX, Inc.
πŸ”Ή Reported By: #ant_pyne
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 16, 2020, 6:35am (UTC)
XSS in desktop client via invalid server address on login form

πŸ‘‰ https://hackerone.com/reports/685552

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #jplopezy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2020, 12:50am (UTC)
Authenticity token doesnt expire after single use leading to CSRF

πŸ‘‰ https://hackerone.com/reports/919112

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Omise
πŸ”Ή Reported By: #justlife_4x4
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 17, 2020, 1:36am (UTC)