Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Graphql: Sorting the reports by jira_status field resulted to different value

πŸ‘‰ https://hackerone.com/reports/955286

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #0619
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 8:27am (UTC)
Stored XSS in eaccounting.stage.vismaonline.com

πŸ‘‰ https://hackerone.com/reports/897523

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #4mat
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 10:26am (UTC)
Null dereference in `cmd_denotify_operation_execute`

πŸ‘‰ https://hackerone.com/reports/965881

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)
Assert failed in `edit_mail_istream_read`

πŸ‘‰ https://hackerone.com/reports/965790

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)
Failed assert in `mail_index_transaction_lookup`

πŸ‘‰ https://hackerone.com/reports/965782

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)
[bl] Uninitialized memory exposure via negative .consume()

πŸ‘‰ https://hackerone.com/reports/966347

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 3:16pm (UTC)
notevil - Sandbox Escape Lead to RCE on Node.js and XSS in the Browser

πŸ‘‰ https://hackerone.com/reports/809012

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #phra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 4:14pm (UTC)
The authenticity_token can be reversed and used to forge valid per_form_csrf_tokens for arbitrary routes

πŸ‘‰ https://hackerone.com/reports/732415

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: #jregele
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 4:25pm (UTC)
CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files

πŸ‘‰ https://hackerone.com/reports/943255

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Khan Academy
πŸ”Ή Reported By: #demonia
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 6:56pm (UTC)
Ability to publish a paid theme without purchasing it.

πŸ‘‰ https://hackerone.com/reports/927567

πŸ”Ή Severity: Low | πŸ’° 2,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #saltymermaid
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 7:41pm (UTC)
Ability to publish a paid theme without purchasing it.

πŸ‘‰ https://hackerone.com/reports/953083

πŸ”Ή Severity: Low | πŸ’° 2,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #saltymermaid
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 7:42pm (UTC)
XSS from arbitrary attachment upload.

πŸ‘‰ https://hackerone.com/reports/831703

πŸ”Ή Severity: High
πŸ”Ή Reported To: Qulture.Rocks
πŸ”Ή Reported By: #wisp
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2020, 4:53am (UTC)
XSS via unicode characters in upload filename

πŸ‘‰ https://hackerone.com/reports/179695

πŸ”Ή Severity: Medium | πŸ’° 600 USD
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: #kahoots
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2020, 4:43pm (UTC)
Remote Code Execution in Slack desktop apps + bonus

πŸ‘‰ https://hackerone.com/reports/783877

πŸ”Ή Severity: Critical | πŸ’° 1,750 USD
πŸ”Ή Reported To: Slack
πŸ”Ή Reported By: #oskarsv
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2020, 6:04pm (UTC)
Private leaderboard owner email disclosure when sending invites

πŸ‘‰ https://hackerone.com/reports/969988

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: WakaTime
πŸ”Ή Reported By: #hy76t56f565
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2020, 11:15pm (UTC)
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com

πŸ‘‰ https://hackerone.com/reports/964550

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #zerox4
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 30, 2020, 3:06pm (UTC)
[sirloin] Web Server Directory Traversal via Crafted GET Request

πŸ‘‰ https://hackerone.com/reports/790623

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #bp0lr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 30, 2020, 3:54pm (UTC)
[hangersteak] Web Server Directory Traversal via Crafted GET Request

πŸ‘‰ https://hackerone.com/reports/790873

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #bp0lr
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 30, 2020, 3:56pm (UTC)
DOM XSS triggered in secure support desk

πŸ‘‰ https://hackerone.com/reports/512065

πŸ”Ή Severity: Critical | πŸ’° 500 USD
πŸ”Ή Reported To: QIWI
πŸ”Ή Reported By: #honoki
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 31, 2020, 10:06am (UTC)
An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing

πŸ‘‰ https://hackerone.com/reports/731878

πŸ”Ή Severity: Medium | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #jianjun
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 31, 2020, 12:53pm (UTC)
[self?] XSS Π² адрСсС ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Ρ [sbermarket.ru]

πŸ‘‰ https://hackerone.com/reports/900973

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #pisarenko
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 31, 2020, 1:00pm (UTC)