Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Java: CWE-522 Insecure basic authentication

πŸ‘‰ https://hackerone.com/reports/963815

πŸ”Ή Severity: High | πŸ’° 2,300 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #luchua
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:51pm (UTC)
Registering with email [ +70 Chars ] Lead to Disclose some informations [Django Debug Mode ]

πŸ‘‰ https://hackerone.com/reports/963584

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #elmahdi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:41am (UTC)
Information Disclosure through DEBUG at Subscription [https://app.dropcontact.io/app/subscription?connector=salesforce](CRITICAL)

πŸ‘‰ https://hackerone.com/reports/963921

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #try___for_impossible
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:53am (UTC)
[javascript] CWE-117: CodeQL query to detect Log Injection

πŸ‘‰ https://hackerone.com/reports/963816

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 20, 2020, 9:51pm (UTC)
Django DEBUG mode enabled and leaked system information.

πŸ‘‰ https://hackerone.com/reports/963542

πŸ”Ή Severity: High
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #aungkyawphyo
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:12am (UTC)
Prototype Pollution lodash 4.17.15

πŸ‘‰ https://hackerone.com/reports/864701

πŸ”Ή Severity: High | πŸ’° 250 USD
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #awarau
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 10:34am (UTC)
Sensitive Information Disclosure

πŸ‘‰ https://hackerone.com/reports/963352

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #exploit_db
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 1:19pm (UTC)
Django should not have debug mode enabled

πŸ‘‰ https://hackerone.com/reports/963809

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #higbee
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 2:38pm (UTC)
Django debug enabled showing information about system, database, configuration files.

πŸ‘‰ https://hackerone.com/reports/963164

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #vbdev
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 7:52pm (UTC)
Unauthorized Use of Victim Credit Card

πŸ‘‰ https://hackerone.com/reports/391385

πŸ”Ή Severity: High | πŸ’° 400 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:20pm (UTC)
ClickJacking on IMPORTANT Functions of Yelp

πŸ‘‰ https://hackerone.com/reports/305128

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:41pm (UTC)
CRITICAL-CLICKJACKING at Yelp Reservations Resulting in exposure of victim Private Data (Email info) + Victim Credit Card MissUse.

πŸ‘‰ https://hackerone.com/reports/355859

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #hk755a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 21, 2020, 8:51pm (UTC)
[extra-asciinema] Command Injection via insecure command formatting

πŸ‘‰ https://hackerone.com/reports/863956

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 22, 2020, 8:48am (UTC)
[meemo-app] Denial of Service via LDAP Injection

πŸ‘‰ https://hackerone.com/reports/907311

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 22, 2020, 8:48am (UTC)
[cloudron-surfer] Denial of Service via LDAP Injection

πŸ‘‰ https://hackerone.com/reports/906959

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 22, 2020, 8:48am (UTC)
Pentester can obtain information about other pentesters who applied for the same test, but weren't accepted

πŸ‘‰ https://hackerone.com/reports/958374

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #haxta4ok00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 9:39am (UTC)
User registration using public domain email like gmail in place of professional email.

πŸ‘‰ https://hackerone.com/reports/963546

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #cyc0rpion
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:21am (UTC)
Null dereference in mcht_relational_validate ext-relational-common.c:136

πŸ‘‰ https://hackerone.com/reports/894446

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 11:42am (UTC)
No Valid SPF Records

πŸ‘‰ https://hackerone.com/reports/962909

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #harshita174
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: August 24, 2020, 2:38pm (UTC)
Stored XSS via "my recent queries" selector in NRQL dashboard builder

πŸ‘‰ https://hackerone.com/reports/626082

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 2:58pm (UTC)
NRQL Query allows restricted user to pull all data from Synthetics monitors without having read permissions enabled

πŸ‘‰ https://hackerone.com/reports/387290

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:00pm (UTC)