Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Rate Limit too lenient for endpoint sending emails

πŸ‘‰ https://hackerone.com/reports/658089

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: WakaTime
πŸ”Ή Reported By: #harshita174
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 19, 2020, 3:11pm (UTC)
Ability to generate shipping labels in another store orders

πŸ‘‰ https://hackerone.com/reports/884159

πŸ”Ή Severity: No Rating | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 19, 2020, 5:58pm (UTC)
[vboxmanage.js] Command Injection via insecure command concatenation

πŸ‘‰ https://hackerone.com/reports/864777

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:08am (UTC)
[object-path-set] Prototype pollution

πŸ‘‰ https://hackerone.com/reports/878332

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:08am (UTC)
[extra-ffmpeg] Command Injection via insecure command formatting

πŸ‘‰ https://hackerone.com/reports/863944

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:08am (UTC)
[supermixer] Prototype pollution

πŸ‘‰ https://hackerone.com/reports/959987

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #0x1337r00t
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 11:10am (UTC)
Insufficient validation on Digits bridge

πŸ‘‰ https://hackerone.com/reports/168116

πŸ”Ή Severity: No Rating | πŸ’° 5,040 USD
πŸ”Ή Reported To: Twitter
πŸ”Ή Reported By: #filedescriptor
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 11:20am (UTC)
API key is not validated for C.R.M integration [Pipedrive] of LOGGED IN USER, A user can use another USER'S API key for this operation.

πŸ‘‰ https://hackerone.com/reports/962033

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #try___for_impossible
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 2:16pm (UTC)
DOM XSS on duckduckgo.com search

πŸ‘‰ https://hackerone.com/reports/921635

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: DuckDuckGo
πŸ”Ή Reported By: #sijisu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 3:49pm (UTC)
Dropcontact's disclosed report is exposing Private/Confidential information

πŸ‘‰ https://hackerone.com/reports/963327

πŸ”Ή Severity: High
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #n1m0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 4:16pm (UTC)
Java: CWE-522 Insecure basic authentication

πŸ‘‰ https://hackerone.com/reports/963815

πŸ”Ή Severity: High | πŸ’° 2,300 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #luchua
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:51pm (UTC)
Registering with email [ +70 Chars ] Lead to Disclose some informations [Django Debug Mode ]

πŸ‘‰ https://hackerone.com/reports/963584

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #elmahdi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:41am (UTC)
Information Disclosure through DEBUG at Subscription [https://app.dropcontact.io/app/subscription?connector=salesforce](CRITICAL)

πŸ‘‰ https://hackerone.com/reports/963921

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #try___for_impossible
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:53am (UTC)
[javascript] CWE-117: CodeQL query to detect Log Injection

πŸ‘‰ https://hackerone.com/reports/963816

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:51pm (UTC)
Django DEBUG mode enabled and leaked system information.

πŸ‘‰ https://hackerone.com/reports/963542

πŸ”Ή Severity: High
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #aungkyawphyo
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:12am (UTC)
Prototype Pollution lodash 4.17.15

πŸ‘‰ https://hackerone.com/reports/864701

πŸ”Ή Severity: High | πŸ’° 250 USD
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #awarau
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 10:34am (UTC)
Sensitive Information Disclosure

πŸ‘‰ https://hackerone.com/reports/963352

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #exploit_db
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 1:19pm (UTC)
Django should not have debug mode enabled

πŸ‘‰ https://hackerone.com/reports/963809

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #higbee
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 2:38pm (UTC)
Django debug enabled showing information about system, database, configuration files.

πŸ‘‰ https://hackerone.com/reports/963164

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #vbdev
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:52pm (UTC)
Unauthorized Use of Victim Credit Card

πŸ‘‰ https://hackerone.com/reports/391385

πŸ”Ή Severity: High | πŸ’° 400 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:20pm (UTC)
ClickJacking on IMPORTANT Functions of Yelp

πŸ‘‰ https://hackerone.com/reports/305128

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:41pm (UTC)