Assert failed in `edit_mail_istream_read`
๐ https://hackerone.com/reports/965790
๐น Severity: No Rating | ๐ฐ 50 USD
๐น Reported To: Open-Xchange
๐น Reported By: #catenacyber
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 11:20am (UTC)
๐ https://hackerone.com/reports/965790
๐น Severity: No Rating | ๐ฐ 50 USD
๐น Reported To: Open-Xchange
๐น Reported By: #catenacyber
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 11:20am (UTC)
Failed assert in `mail_index_transaction_lookup`
๐ https://hackerone.com/reports/965782
๐น Severity: No Rating | ๐ฐ 50 USD
๐น Reported To: Open-Xchange
๐น Reported By: #catenacyber
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 11:20am (UTC)
๐ https://hackerone.com/reports/965782
๐น Severity: No Rating | ๐ฐ 50 USD
๐น Reported To: Open-Xchange
๐น Reported By: #catenacyber
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 11:20am (UTC)
[bl] Uninitialized memory exposure via negative .consume()
๐ https://hackerone.com/reports/966347
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #chalker
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 3:16pm (UTC)
๐ https://hackerone.com/reports/966347
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #chalker
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 3:16pm (UTC)
notevil - Sandbox Escape Lead to RCE on Node.js and XSS in the Browser
๐ https://hackerone.com/reports/809012
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #phra
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 4:14pm (UTC)
๐ https://hackerone.com/reports/809012
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #phra
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 4:14pm (UTC)
The authenticity_token can be reversed and used to forge valid per_form_csrf_tokens for arbitrary routes
๐ https://hackerone.com/reports/732415
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #jregele
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 4:25pm (UTC)
๐ https://hackerone.com/reports/732415
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #jregele
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 4:25pm (UTC)
CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files
๐ https://hackerone.com/reports/943255
๐น Severity: Medium
๐น Reported To: Khan Academy
๐น Reported By: #demonia
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 6:56pm (UTC)
๐ https://hackerone.com/reports/943255
๐น Severity: Medium
๐น Reported To: Khan Academy
๐น Reported By: #demonia
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 6:56pm (UTC)
Ability to publish a paid theme without purchasing it.
๐ https://hackerone.com/reports/927567
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:41pm (UTC)
๐ https://hackerone.com/reports/927567
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:41pm (UTC)
Ability to publish a paid theme without purchasing it.
๐ https://hackerone.com/reports/953083
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:42pm (UTC)
๐ https://hackerone.com/reports/953083
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:42pm (UTC)
XSS from arbitrary attachment upload.
๐ https://hackerone.com/reports/831703
๐น Severity: High
๐น Reported To: Qulture.Rocks
๐น Reported By: #wisp
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:53am (UTC)
๐ https://hackerone.com/reports/831703
๐น Severity: High
๐น Reported To: Qulture.Rocks
๐น Reported By: #wisp
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:53am (UTC)
XSS via unicode characters in upload filename
๐ https://hackerone.com/reports/179695
๐น Severity: Medium | ๐ฐ 600 USD
๐น Reported To: WordPress
๐น Reported By: #kahoots
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:43pm (UTC)
๐ https://hackerone.com/reports/179695
๐น Severity: Medium | ๐ฐ 600 USD
๐น Reported To: WordPress
๐น Reported By: #kahoots
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:43pm (UTC)
Remote Code Execution in Slack desktop apps + bonus
๐ https://hackerone.com/reports/783877
๐น Severity: Critical | ๐ฐ 1,750 USD
๐น Reported To: Slack
๐น Reported By: #oskarsv
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 6:04pm (UTC)
๐ https://hackerone.com/reports/783877
๐น Severity: Critical | ๐ฐ 1,750 USD
๐น Reported To: Slack
๐น Reported By: #oskarsv
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 6:04pm (UTC)
Private leaderboard owner email disclosure when sending invites
๐ https://hackerone.com/reports/969988
๐น Severity: No Rating
๐น Reported To: WakaTime
๐น Reported By: #hy76t56f565
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 11:15pm (UTC)
๐ https://hackerone.com/reports/969988
๐น Severity: No Rating
๐น Reported To: WakaTime
๐น Reported By: #hy76t56f565
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 11:15pm (UTC)
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com
๐ https://hackerone.com/reports/964550
๐น Severity: Low
๐น Reported To: Shopify
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:06pm (UTC)
๐ https://hackerone.com/reports/964550
๐น Severity: Low
๐น Reported To: Shopify
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:06pm (UTC)
[sirloin] Web Server Directory Traversal via Crafted GET Request
๐ https://hackerone.com/reports/790623
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:54pm (UTC)
๐ https://hackerone.com/reports/790623
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:54pm (UTC)
[hangersteak] Web Server Directory Traversal via Crafted GET Request
๐ https://hackerone.com/reports/790873
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:56pm (UTC)
๐ https://hackerone.com/reports/790873
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:56pm (UTC)
DOM XSS triggered in secure support desk
๐ https://hackerone.com/reports/512065
๐น Severity: Critical | ๐ฐ 500 USD
๐น Reported To: QIWI
๐น Reported By: #honoki
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 10:06am (UTC)
๐ https://hackerone.com/reports/512065
๐น Severity: Critical | ๐ฐ 500 USD
๐น Reported To: QIWI
๐น Reported By: #honoki
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 10:06am (UTC)
An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing
๐ https://hackerone.com/reports/731878
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #jianjun
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 12:53pm (UTC)
๐ https://hackerone.com/reports/731878
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #jianjun
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 12:53pm (UTC)
[self?] XSS ะฒ ะฐะดัะตัะต ะฟะพะปัะทะพะฒะฐัะตะปั [sbermarket.ru]
๐ https://hackerone.com/reports/900973
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #pisarenko
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 1:00pm (UTC)
๐ https://hackerone.com/reports/900973
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #pisarenko
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 1:00pm (UTC)
Access to information about any video and its owner via GraphQL endpoint [dictor.mail.ru]
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
IDOR ะฟะพะทะฒะพะปัะตั ะธะทะผะตะฝะธัั ะธะฝัะพัะผะฐัะธั ะพ ะฟะพะปัะทะพะฒะฐัะตะปะต.
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
warofdragons.my.games: configuration files with database account are accessible
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)