Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties ๐Ÿ“ฃ

Rate๐Ÿ‘‡
https://cutt.ly/bugpoint_rate
Feedback๐Ÿ‘‡
https://cutt.ly/bugpoint_feedback

#๏ธโƒฃ bug bounty disclosed reports
#๏ธโƒฃ bug bounty write-ups
#๏ธโƒฃ bug bounty teleg
Download Telegram
Assert failed in `edit_mail_istream_read`

๐Ÿ‘‰ https://hackerone.com/reports/965790

๐Ÿ”น Severity: No Rating | ๐Ÿ’ฐ 50 USD
๐Ÿ”น Reported To: Open-Xchange
๐Ÿ”น Reported By: #catenacyber
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 11:20am (UTC)
Failed assert in `mail_index_transaction_lookup`

๐Ÿ‘‰ https://hackerone.com/reports/965782

๐Ÿ”น Severity: No Rating | ๐Ÿ’ฐ 50 USD
๐Ÿ”น Reported To: Open-Xchange
๐Ÿ”น Reported By: #catenacyber
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 11:20am (UTC)
[bl] Uninitialized memory exposure via negative .consume()

๐Ÿ‘‰ https://hackerone.com/reports/966347

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #chalker
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 3:16pm (UTC)
notevil - Sandbox Escape Lead to RCE on Node.js and XSS in the Browser

๐Ÿ‘‰ https://hackerone.com/reports/809012

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #phra
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 4:14pm (UTC)
The authenticity_token can be reversed and used to forge valid per_form_csrf_tokens for arbitrary routes

๐Ÿ‘‰ https://hackerone.com/reports/732415

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 500 USD
๐Ÿ”น Reported To: Ruby on Rails
๐Ÿ”น Reported By: #jregele
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 4:25pm (UTC)
CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files

๐Ÿ‘‰ https://hackerone.com/reports/943255

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Khan Academy
๐Ÿ”น Reported By: #demonia
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 6:56pm (UTC)
Ability to publish a paid theme without purchasing it.

๐Ÿ‘‰ https://hackerone.com/reports/927567

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 2,000 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #saltymermaid
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 7:41pm (UTC)
Ability to publish a paid theme without purchasing it.

๐Ÿ‘‰ https://hackerone.com/reports/953083

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 2,000 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #saltymermaid
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 7:42pm (UTC)
XSS from arbitrary attachment upload.

๐Ÿ‘‰ https://hackerone.com/reports/831703

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Qulture.Rocks
๐Ÿ”น Reported By: #wisp
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 4:53am (UTC)
XSS via unicode characters in upload filename

๐Ÿ‘‰ https://hackerone.com/reports/179695

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 600 USD
๐Ÿ”น Reported To: WordPress
๐Ÿ”น Reported By: #kahoots
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 4:43pm (UTC)
Remote Code Execution in Slack desktop apps + bonus

๐Ÿ‘‰ https://hackerone.com/reports/783877

๐Ÿ”น Severity: Critical | ๐Ÿ’ฐ 1,750 USD
๐Ÿ”น Reported To: Slack
๐Ÿ”น Reported By: #oskarsv
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 6:04pm (UTC)
Private leaderboard owner email disclosure when sending invites

๐Ÿ‘‰ https://hackerone.com/reports/969988

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: WakaTime
๐Ÿ”น Reported By: #hy76t56f565
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 11:15pm (UTC)
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com

๐Ÿ‘‰ https://hackerone.com/reports/964550

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #zerox4
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:06pm (UTC)
[sirloin] Web Server Directory Traversal via Crafted GET Request

๐Ÿ‘‰ https://hackerone.com/reports/790623

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #bp0lr
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:54pm (UTC)
[hangersteak] Web Server Directory Traversal via Crafted GET Request

๐Ÿ‘‰ https://hackerone.com/reports/790873

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #bp0lr
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:56pm (UTC)
DOM XSS triggered in secure support desk

๐Ÿ‘‰ https://hackerone.com/reports/512065

๐Ÿ”น Severity: Critical | ๐Ÿ’ฐ 500 USD
๐Ÿ”น Reported To: QIWI
๐Ÿ”น Reported By: #honoki
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 10:06am (UTC)
An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing

๐Ÿ‘‰ https://hackerone.com/reports/731878

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 150 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #jianjun
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 12:53pm (UTC)
[self?] XSS ะฒ ะฐะดั€ะตัะต ะฟะพะปัŒะทะพะฒะฐั‚ะตะปั [sbermarket.ru]

๐Ÿ‘‰ https://hackerone.com/reports/900973

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #pisarenko
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 1:00pm (UTC)
Access to information about any video and its owner via GraphQL endpoint [dictor.mail.ru]

๐Ÿ‘‰ https://hackerone.com/reports/924914

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 2,500 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #organdonor
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:14am (UTC)
IDOR ะฟะพะทะฒะพะปัะตั‚ ะธะทะผะตะฝะธั‚ัŒ ะธะฝั„ะพั€ะผะฐั†ะธัŽ ะพ ะฟะพะปัŒะทะพะฒะฐั‚ะตะปะต.

๐Ÿ‘‰ https://hackerone.com/reports/708182

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #iframe
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:21am (UTC)
warofdragons.my.games: configuration files with database account are accessible

๐Ÿ‘‰ https://hackerone.com/reports/786609

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 150 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #iframe
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:24am (UTC)