Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Solution for XSS challenge calc.buggywebsite.com

πŸ‘‰ https://hackerone.com/reports/954249

πŸ”Ή Severity: High
πŸ”Ή Reported To: BugPoC
πŸ”Ή Reported By: #d1r3wolf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 15, 2020, 6:32pm (UTC)
Unrestricted File Upload in Chat Window

πŸ‘‰ https://hackerone.com/reports/925513

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: OWOX, Inc.
πŸ”Ή Reported By: #ant_pyne
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 16, 2020, 6:35am (UTC)
XSS in desktop client via invalid server address on login form

πŸ‘‰ https://hackerone.com/reports/685552

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #jplopezy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2020, 12:50am (UTC)
Authenticity token doesnt expire after single use leading to CSRF

πŸ‘‰ https://hackerone.com/reports/919112

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Omise
πŸ”Ή Reported By: #justlife_4x4
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 17, 2020, 1:36am (UTC)
RTLO character allowed in shared files

πŸ‘‰ https://hackerone.com/reports/229170

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #inhibitor181
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 17, 2020, 8:34am (UTC)
Linux client is vulnerable to directory traversal when downloading files

πŸ‘‰ https://hackerone.com/reports/590319

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #icewater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2020, 12:57pm (UTC)
SSRF In plantuml (on plantuml.pre.gitlab.com)

πŸ‘‰ https://hackerone.com/reports/689245

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #plazmaz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 17, 2020, 1:55pm (UTC)
i don't the important and it's impact . the affected asset : https://github.com/solana-labs/solana/blob/master/.buildkite/env/secrets.ejson

πŸ‘‰ https://hackerone.com/reports/961167

πŸ”Ή Severity: High
πŸ”Ή Reported To: Solana BBP
πŸ”Ή Reported By: #hussein_mersal
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: August 18, 2020, 2:44am (UTC)
i don't the important and it's impact . the affected asset: https://github.com/solana-labs/solana/blob/master/.buildkite/env/secrets.ejson

πŸ‘‰ https://hackerone.com/reports/961175

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Solana BBP
πŸ”Ή Reported By: #hussein_mersal
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: August 18, 2020, 2:47am (UTC)
Sensitive data leaks [username, password, keys]

πŸ‘‰ https://hackerone.com/reports/961170

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Solana BBP
πŸ”Ή Reported By: #anjpan
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 18, 2020, 3:02am (UTC)
Session not invalidated after password reset

πŸ‘‰ https://hackerone.com/reports/917213

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Gener8
πŸ”Ή Reported By: #5hu8h4m_n4g4
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 8:53am (UTC)
pre-auth Stored XSS in comments via javascript: url when administrator edits user supplied comment

πŸ‘‰ https://hackerone.com/reports/633231

πŸ”Ή Severity: High | πŸ’° 650 USD
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: #simonscannell
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 6:01pm (UTC)
Stored XSS in Post Preview as Contributor

πŸ‘‰ https://hackerone.com/reports/497724

πŸ”Ή Severity: Medium | πŸ’° 650 USD
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: #simonscannell
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 6:02pm (UTC)
Blind Stored XSS Via Staff Name

πŸ‘‰ https://hackerone.com/reports/948929

πŸ”Ή Severity: High | πŸ’° 3,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #rioncool22
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 7:41pm (UTC)
access permission is not revoked even if the email has been deleted or changed on the partner account -partners.shopify-

πŸ‘‰ https://hackerone.com/reports/870001

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #jaka_tingkir
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 7:44pm (UTC)
OrderListInitial leaks order details

πŸ‘‰ https://hackerone.com/reports/882412

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #sreeju_kc
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 7:52pm (UTC)
Get analytics token using only apps permission

πŸ‘‰ https://hackerone.com/reports/901775

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #jmp_35p
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 9:29pm (UTC)
Some store settings/data are accessible to "No Access" permission users on GraphQL LiveView operation

πŸ‘‰ https://hackerone.com/reports/409973

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #tolo7010
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 10:09pm (UTC)
Korea - Reflected XSS on https://www.istarbucks.co.kr/app/getGiftStock.do via "skuNo" and "skuImgUrl" parameters

πŸ‘‰ https://hackerone.com/reports/768345

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Starbucks
πŸ”Ή Reported By: #rexvuz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 10:38pm (UTC)
Password reset link not expired at Stocky App

πŸ‘‰ https://hackerone.com/reports/898841

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ayyoub
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 18, 2020, 10:53pm (UTC)
I.D.O.R TO EDIT ALL USER'S CREDIT CARD INFORMATION+(Partial credit card info disclosure)

πŸ‘‰ https://hackerone.com/reports/361984

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 19, 2020, 12:59am (UTC)