Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
*.shopify.com - Authentication bypass

πŸ‘‰ https://hackerone.com/reports/838231

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #nooblife
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:18pm (UTC)
STAFF "No-Permissions" on the Store can retrieve the details Order via exchangeReceiptSend

πŸ‘‰ https://hackerone.com/reports/917875

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #langduvnsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 4:41pm (UTC)
[com.smule.autorap.*] Cloud Messaging/Push Notification service takeover due to clear-text usage of Legacy FCM Server keys in the client app

πŸ‘‰ https://hackerone.com/reports/789370

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Smule
πŸ”Ή Reported By: #absshax
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 7:27pm (UTC)
Stocky App Administrator can create a backdoor admin account by using an existing POS User

πŸ‘‰ https://hackerone.com/reports/962895

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 9:58pm (UTC)
[windows-edge] RCE via insecure command formatting

πŸ‘‰ https://hackerone.com/reports/878420

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #mik317
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:04pm (UTC)
Path Traversal in App Proxy

πŸ‘‰ https://hackerone.com/reports/869888

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ngalog
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2020, 10:27pm (UTC)
Prototype pollution attack (lodash)

πŸ‘‰ https://hackerone.com/reports/841380

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #macasun
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 9:26am (UTC)
Recently added 'Country' field doesn't send email notification when changed

πŸ‘‰ https://hackerone.com/reports/961841

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #bugra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 10:57am (UTC)
Ability to see password protected content by bypassing the password page of shopify preview URL for new development stores (as of August 17, 2020)

πŸ‘‰ https://hackerone.com/reports/961929

πŸ”Ή Severity: No Rating | πŸ’° 1,500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #saltymermaid
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 3:55pm (UTC)
Stored XSS on Broken Themes via filename

πŸ‘‰ https://hackerone.com/reports/406289

πŸ”Ή Severity: Low | πŸ’° 300 USD
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: #apapedulimu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 3:56pm (UTC)
Self XSS in Timeline

πŸ‘‰ https://hackerone.com/reports/854299

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ryat
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 5:04pm (UTC)
Script Editor preview token still working with uninstalled application, even for unpublished script

πŸ‘‰ https://hackerone.com/reports/915940

πŸ”Ή Severity: No Rating | πŸ’° 2,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 9:34pm (UTC)
[json-bigint] DoS via `__proto__` assignment

πŸ‘‰ https://hackerone.com/reports/916430

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 10:40pm (UTC)
[min-http-server] List any file in the folder by using path traversal.

πŸ‘‰ https://hackerone.com/reports/569891

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #toannc123
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:20am (UTC)
Information disclosure to "Permission as auditor" user

πŸ‘‰ https://hackerone.com/reports/959897

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #risinghunter
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 5:09am (UTC)
[New Relic Infrastructure] Restricted User can still integrate with AWS via forced browsing (plus, a few other bugs)

πŸ‘‰ https://hackerone.com/reports/255685

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:51am (UTC)
[NR Synthetics] Restricted user can view synthetics monitors and user permissions through .json endpoint at /permissions/securablemetadata/{GROUP ID}

πŸ‘‰ https://hackerone.com/reports/320689

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:54am (UTC)
Adding a new user discloses their full name in the "Users" section of NR Alerts notification channels page

πŸ‘‰ https://hackerone.com/reports/344309

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:57am (UTC)
Internal API endpoint discloses full account name of email address associated with unconfirmed user

πŸ‘‰ https://hackerone.com/reports/332381

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:59am (UTC)
Initial mirror user can be assigned by other user even if the mirror was removed

πŸ‘‰ https://hackerone.com/reports/819821

πŸ”Ή Severity: Medium | πŸ’° 3,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #sky003
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 1:52pm (UTC)
Stealing data from customers.gitlab.com without user interaction

πŸ‘‰ https://hackerone.com/reports/674195

πŸ”Ή Severity: High | πŸ’° 3,500 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #rpadovani
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:02pm (UTC)