CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files
๐ https://hackerone.com/reports/943255
๐น Severity: Medium
๐น Reported To: Khan Academy
๐น Reported By: #demonia
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 6:56pm (UTC)
๐ https://hackerone.com/reports/943255
๐น Severity: Medium
๐น Reported To: Khan Academy
๐น Reported By: #demonia
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 6:56pm (UTC)
Ability to publish a paid theme without purchasing it.
๐ https://hackerone.com/reports/927567
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:41pm (UTC)
๐ https://hackerone.com/reports/927567
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:41pm (UTC)
Ability to publish a paid theme without purchasing it.
๐ https://hackerone.com/reports/953083
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:42pm (UTC)
๐ https://hackerone.com/reports/953083
๐น Severity: Low | ๐ฐ 2,000 USD
๐น Reported To: Shopify
๐น Reported By: #saltymermaid
๐น State: ๐ข Resolved
๐น Disclosed: August 27, 2020, 7:42pm (UTC)
XSS from arbitrary attachment upload.
๐ https://hackerone.com/reports/831703
๐น Severity: High
๐น Reported To: Qulture.Rocks
๐น Reported By: #wisp
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:53am (UTC)
๐ https://hackerone.com/reports/831703
๐น Severity: High
๐น Reported To: Qulture.Rocks
๐น Reported By: #wisp
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:53am (UTC)
XSS via unicode characters in upload filename
๐ https://hackerone.com/reports/179695
๐น Severity: Medium | ๐ฐ 600 USD
๐น Reported To: WordPress
๐น Reported By: #kahoots
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:43pm (UTC)
๐ https://hackerone.com/reports/179695
๐น Severity: Medium | ๐ฐ 600 USD
๐น Reported To: WordPress
๐น Reported By: #kahoots
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 4:43pm (UTC)
Remote Code Execution in Slack desktop apps + bonus
๐ https://hackerone.com/reports/783877
๐น Severity: Critical | ๐ฐ 1,750 USD
๐น Reported To: Slack
๐น Reported By: #oskarsv
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 6:04pm (UTC)
๐ https://hackerone.com/reports/783877
๐น Severity: Critical | ๐ฐ 1,750 USD
๐น Reported To: Slack
๐น Reported By: #oskarsv
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 6:04pm (UTC)
Private leaderboard owner email disclosure when sending invites
๐ https://hackerone.com/reports/969988
๐น Severity: No Rating
๐น Reported To: WakaTime
๐น Reported By: #hy76t56f565
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 11:15pm (UTC)
๐ https://hackerone.com/reports/969988
๐น Severity: No Rating
๐น Reported To: WakaTime
๐น Reported By: #hy76t56f565
๐น State: ๐ข Resolved
๐น Disclosed: August 28, 2020, 11:15pm (UTC)
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com
๐ https://hackerone.com/reports/964550
๐น Severity: Low
๐น Reported To: Shopify
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:06pm (UTC)
๐ https://hackerone.com/reports/964550
๐น Severity: Low
๐น Reported To: Shopify
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:06pm (UTC)
[sirloin] Web Server Directory Traversal via Crafted GET Request
๐ https://hackerone.com/reports/790623
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:54pm (UTC)
๐ https://hackerone.com/reports/790623
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:54pm (UTC)
[hangersteak] Web Server Directory Traversal via Crafted GET Request
๐ https://hackerone.com/reports/790873
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:56pm (UTC)
๐ https://hackerone.com/reports/790873
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #bp0lr
๐น State: ๐ข Resolved
๐น Disclosed: August 30, 2020, 3:56pm (UTC)
DOM XSS triggered in secure support desk
๐ https://hackerone.com/reports/512065
๐น Severity: Critical | ๐ฐ 500 USD
๐น Reported To: QIWI
๐น Reported By: #honoki
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 10:06am (UTC)
๐ https://hackerone.com/reports/512065
๐น Severity: Critical | ๐ฐ 500 USD
๐น Reported To: QIWI
๐น Reported By: #honoki
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 10:06am (UTC)
An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing
๐ https://hackerone.com/reports/731878
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #jianjun
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 12:53pm (UTC)
๐ https://hackerone.com/reports/731878
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #jianjun
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 12:53pm (UTC)
[self?] XSS ะฒ ะฐะดัะตัะต ะฟะพะปัะทะพะฒะฐัะตะปั [sbermarket.ru]
๐ https://hackerone.com/reports/900973
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #pisarenko
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 1:00pm (UTC)
๐ https://hackerone.com/reports/900973
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #pisarenko
๐น State: ๐ข Resolved
๐น Disclosed: August 31, 2020, 1:00pm (UTC)
Access to information about any video and its owner via GraphQL endpoint [dictor.mail.ru]
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
IDOR ะฟะพะทะฒะพะปัะตั ะธะทะผะตะฝะธัั ะธะฝัะพัะผะฐัะธั ะพ ะฟะพะปัะทะพะฒะฐัะตะปะต.
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
warofdragons.my.games: configuration files with database account are accessible
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)
[garnier-olia.lady.mail.ru] Reflected XSS /exp/ bypass "/"
๐ https://hackerone.com/reports/787815
๐น Severity: Low
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:26am (UTC)
๐ https://hackerone.com/reports/787815
๐น Severity: Low
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:26am (UTC)
Clickjacking lead to remove review
๐ https://hackerone.com/reports/965141
๐น Severity: Medium
๐น Reported To: Yelp
๐น Reported By: #alaayousef
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 6:07pm (UTC)
๐ https://hackerone.com/reports/965141
๐น Severity: Medium
๐น Reported To: Yelp
๐น Reported By: #alaayousef
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 6:07pm (UTC)
CRLF injection on www.starbucks.com
๐ https://hackerone.com/reports/858650
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Starbucks
๐น Reported By: #x3n0nn3p
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:59pm (UTC)
๐ https://hackerone.com/reports/858650
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Starbucks
๐น Reported By: #x3n0nn3p
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:59pm (UTC)
XSS by file (Active Storage `Proxying`)
๐ https://hackerone.com/reports/949513
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #ooooooo_q
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 10:51pm (UTC)
๐ https://hackerone.com/reports/949513
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #ooooooo_q
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 10:51pm (UTC)
Stored XSS in Post title (PoC)
๐ https://hackerone.com/reports/942859
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Imgur
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:06am (UTC)
๐ https://hackerone.com/reports/942859
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Imgur
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:06am (UTC)