Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
[meemo-app] Denial of Service via LDAP Injection

πŸ‘‰ https://hackerone.com/reports/907311

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 22, 2020, 8:48am (UTC)
[cloudron-surfer] Denial of Service via LDAP Injection

πŸ‘‰ https://hackerone.com/reports/906959

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #d3lla
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 22, 2020, 8:48am (UTC)
Pentester can obtain information about other pentesters who applied for the same test, but weren't accepted

πŸ‘‰ https://hackerone.com/reports/958374

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #haxta4ok00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 9:39am (UTC)
User registration using public domain email like gmail in place of professional email.

πŸ‘‰ https://hackerone.com/reports/963546

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #cyc0rpion
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:21am (UTC)
Null dereference in mcht_relational_validate ext-relational-common.c:136

πŸ‘‰ https://hackerone.com/reports/894446

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 11:42am (UTC)
No Valid SPF Records

πŸ‘‰ https://hackerone.com/reports/962909

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropcontact
πŸ”Ή Reported By: #harshita174
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: August 24, 2020, 2:38pm (UTC)
Stored XSS via "my recent queries" selector in NRQL dashboard builder

πŸ‘‰ https://hackerone.com/reports/626082

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 2:58pm (UTC)
NRQL Query allows restricted user to pull all data from Synthetics monitors without having read permissions enabled

πŸ‘‰ https://hackerone.com/reports/387290

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:00pm (UTC)
Restricted user can view all account invoices, payment method details, PII of account owner through zoura_api endpoints

πŸ‘‰ https://hackerone.com/reports/501672

πŸ”Ή Severity: Medium | πŸ’° 900 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:01pm (UTC)
(Prerelease UI) Stored XSS via role name in JSON chart

πŸ‘‰ https://hackerone.com/reports/520630

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:03pm (UTC)
Restricted user is able to delete filter sets of admin users in https://infrastructure.newrelic.com/accounts/{{ACC#}}/settings/filterSets

πŸ‘‰ https://hackerone.com/reports/202501

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:07pm (UTC)
SSO bypass in zendesk using trint organization able to leak internal ticket information

πŸ‘‰ https://hackerone.com/reports/734936

πŸ”Ή Severity: High
πŸ”Ή Reported To: Trint Ltd
πŸ”Ή Reported By: #dopaminedetox
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 3:43pm (UTC)
increased privileges on staff account

πŸ‘‰ https://hackerone.com/reports/911857

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #jaka_tingkir
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:05pm (UTC)
xss stored in https://your store.myshopify.com/admin/

πŸ‘‰ https://hackerone.com/reports/887879

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #zwail
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:08pm (UTC)
Subdomain takeover in help.tictail.com pointing to Zendesk (a Shopify acquisition)

πŸ‘‰ https://hackerone.com/reports/869605

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #meow-hacker-meow
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:17pm (UTC)
*.shopify.com - Authentication bypass

πŸ‘‰ https://hackerone.com/reports/838231

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #nooblife
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:18pm (UTC)
STAFF "No-Permissions" on the Store can retrieve the details Order via exchangeReceiptSend

πŸ‘‰ https://hackerone.com/reports/917875

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #langduvnsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:41pm (UTC)
[com.smule.autorap.*] Cloud Messaging/Push Notification service takeover due to clear-text usage of Legacy FCM Server keys in the client app

πŸ‘‰ https://hackerone.com/reports/789370

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Smule
πŸ”Ή Reported By: #absshax
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 7:27pm (UTC)
Stocky App Administrator can create a backdoor admin account by using an existing POS User

πŸ‘‰ https://hackerone.com/reports/962895

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 9:58pm (UTC)
[windows-edge] RCE via insecure command formatting

πŸ‘‰ https://hackerone.com/reports/878420

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #mik317
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:04pm (UTC)
Path Traversal in App Proxy

πŸ‘‰ https://hackerone.com/reports/869888

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ngalog
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:27pm (UTC)