Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties ๐Ÿ“ฃ

Rate๐Ÿ‘‡
https://cutt.ly/bugpoint_rate
Feedback๐Ÿ‘‡
https://cutt.ly/bugpoint_feedback

#๏ธโƒฃ bug bounty disclosed reports
#๏ธโƒฃ bug bounty write-ups
#๏ธโƒฃ bug bounty teleg
Download Telegram
Ability to publish a paid theme without purchasing it.

๐Ÿ‘‰ https://hackerone.com/reports/927567

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 2,000 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #saltymermaid
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 7:41pm (UTC)
Ability to publish a paid theme without purchasing it.

๐Ÿ‘‰ https://hackerone.com/reports/953083

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 2,000 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #saltymermaid
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 27, 2020, 7:42pm (UTC)
XSS from arbitrary attachment upload.

๐Ÿ‘‰ https://hackerone.com/reports/831703

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Qulture.Rocks
๐Ÿ”น Reported By: #wisp
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 4:53am (UTC)
XSS via unicode characters in upload filename

๐Ÿ‘‰ https://hackerone.com/reports/179695

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 600 USD
๐Ÿ”น Reported To: WordPress
๐Ÿ”น Reported By: #kahoots
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 4:43pm (UTC)
Remote Code Execution in Slack desktop apps + bonus

๐Ÿ‘‰ https://hackerone.com/reports/783877

๐Ÿ”น Severity: Critical | ๐Ÿ’ฐ 1,750 USD
๐Ÿ”น Reported To: Slack
๐Ÿ”น Reported By: #oskarsv
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 6:04pm (UTC)
Private leaderboard owner email disclosure when sending invites

๐Ÿ‘‰ https://hackerone.com/reports/969988

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: WakaTime
๐Ÿ”น Reported By: #hy76t56f565
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 28, 2020, 11:15pm (UTC)
XSS Stored via Upload avatar PNG [HTML] File in accounts.shopify.com

๐Ÿ‘‰ https://hackerone.com/reports/964550

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #zerox4
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:06pm (UTC)
[sirloin] Web Server Directory Traversal via Crafted GET Request

๐Ÿ‘‰ https://hackerone.com/reports/790623

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #bp0lr
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:54pm (UTC)
[hangersteak] Web Server Directory Traversal via Crafted GET Request

๐Ÿ‘‰ https://hackerone.com/reports/790873

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Node.js third-party modules
๐Ÿ”น Reported By: #bp0lr
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 30, 2020, 3:56pm (UTC)
DOM XSS triggered in secure support desk

๐Ÿ‘‰ https://hackerone.com/reports/512065

๐Ÿ”น Severity: Critical | ๐Ÿ’ฐ 500 USD
๐Ÿ”น Reported To: QIWI
๐Ÿ”น Reported By: #honoki
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 10:06am (UTC)
An implementation flaw in Mail.ru can be exploited for DKIM signature spoofing and email spoofing

๐Ÿ‘‰ https://hackerone.com/reports/731878

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 150 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #jianjun
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 12:53pm (UTC)
[self?] XSS ะฒ ะฐะดั€ะตัะต ะฟะพะปัŒะทะพะฒะฐั‚ะตะปั [sbermarket.ru]

๐Ÿ‘‰ https://hackerone.com/reports/900973

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #pisarenko
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: August 31, 2020, 1:00pm (UTC)
Access to information about any video and its owner via GraphQL endpoint [dictor.mail.ru]

๐Ÿ‘‰ https://hackerone.com/reports/924914

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 2,500 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #organdonor
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:14am (UTC)
IDOR ะฟะพะทะฒะพะปัะตั‚ ะธะทะผะตะฝะธั‚ัŒ ะธะฝั„ะพั€ะผะฐั†ะธัŽ ะพ ะฟะพะปัŒะทะพะฒะฐั‚ะตะปะต.

๐Ÿ‘‰ https://hackerone.com/reports/708182

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #iframe
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:21am (UTC)
warofdragons.my.games: configuration files with database account are accessible

๐Ÿ‘‰ https://hackerone.com/reports/786609

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 150 USD
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #iframe
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:24am (UTC)
[garnier-olia.lady.mail.ru] Reflected XSS /exp/ bypass "/"

๐Ÿ‘‰ https://hackerone.com/reports/787815

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Mail.ru
๐Ÿ”น Reported By: #iframe
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:26am (UTC)
Clickjacking lead to remove review

๐Ÿ‘‰ https://hackerone.com/reports/965141

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Yelp
๐Ÿ”น Reported By: #alaayousef
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 6:07pm (UTC)
CRLF injection on www.starbucks.com

๐Ÿ‘‰ https://hackerone.com/reports/858650

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 250 USD
๐Ÿ”น Reported To: Starbucks
๐Ÿ”น Reported By: #x3n0nn3p
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 9:59pm (UTC)
XSS by file (Active Storage `Proxying`)

๐Ÿ‘‰ https://hackerone.com/reports/949513

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 500 USD
๐Ÿ”น Reported To: Ruby on Rails
๐Ÿ”น Reported By: #ooooooo_q
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 1, 2020, 10:51pm (UTC)
Stored XSS in Post title (PoC)

๐Ÿ‘‰ https://hackerone.com/reports/942859

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 250 USD
๐Ÿ”น Reported To: Imgur
๐Ÿ”น Reported By: #zerox4
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 2, 2020, 6:06am (UTC)
Takeover an account that doesn't have a Shopify ID and more

๐Ÿ‘‰ https://hackerone.com/reports/867513

๐Ÿ”น Severity: Critical | ๐Ÿ’ฐ 22,500 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #francisbeaudoin
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: September 2, 2020, 2:47pm (UTC)