Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
[garnier-olia.lady.mail.ru] Reflected XSS /exp/ bypass "/"

πŸ‘‰ https://hackerone.com/reports/787815

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #iframe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2020, 9:26am (UTC)
Clickjacking lead to remove review

πŸ‘‰ https://hackerone.com/reports/965141

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #alaayousef
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2020, 6:07pm (UTC)
CRLF injection on www.starbucks.com

πŸ‘‰ https://hackerone.com/reports/858650

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Starbucks
πŸ”Ή Reported By: #x3n0nn3p
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2020, 9:59pm (UTC)
XSS by file (Active Storage `Proxying`)

πŸ‘‰ https://hackerone.com/reports/949513

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: #ooooooo_q
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2020, 10:51pm (UTC)
Stored XSS in Post title (PoC)

πŸ‘‰ https://hackerone.com/reports/942859

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Imgur
πŸ”Ή Reported By: #zerox4
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 6:06am (UTC)
Takeover an account that doesn't have a Shopify ID and more

πŸ‘‰ https://hackerone.com/reports/867513

πŸ”Ή Severity: Critical | πŸ’° 22,500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 2:47pm (UTC)
Public access to Sidekiq dashboard at shopper.sbermarket.ru

πŸ‘‰ https://hackerone.com/reports/951190

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #avolume
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 4:09pm (UTC)
looch.tv CORS crossite user information and stream_key access

πŸ‘‰ https://hackerone.com/reports/708886

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #iframe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 5:43pm (UTC)
[api.33slona.ru] Доступ ΠΊ API ΠΈΠ· Π·Π° Π½Π΅ΠΏΡ€Π°Π²ΠΈΠ»ΡŒΠ½ΠΎΠΉ ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΠΈ сСрвСра 302 Ρ€Π΅Π΄ΠΈΡ€Π΅Ρ‚.

πŸ‘‰ https://hackerone.com/reports/819714

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #iframe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 6:24pm (UTC)
Subdomain Takeover at analyticstest.geekbrains.ru

πŸ‘‰ https://hackerone.com/reports/942179

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #steal_wart
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 6:27pm (UTC)
Denial of Service | twitter.com & mobile.twitter.com

πŸ‘‰ https://hackerone.com/reports/903740

πŸ”Ή Severity: Medium | πŸ’° 1,120 USD
πŸ”Ή Reported To: Twitter
πŸ”Ή Reported By: #cyanpiny
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2020, 7:18pm (UTC)
IDOR in locid parameter allowing to view others accounts Profile Locations

πŸ‘‰ https://hackerone.com/reports/966949

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #cocoh__23
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 2, 2020, 7:26pm (UTC)
[static-server-gx] Path Traversal allowing to read any files on the server

πŸ‘‰ https://hackerone.com/reports/581939

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #lightangel1412
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 12:44am (UTC)
Open SonarQube instance leaking internal source code

πŸ‘‰ https://hackerone.com/reports/947946

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Equifax
πŸ”Ή Reported By: #aksquare
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:59am (UTC)
SQL injection at fleet.city-mobil.ru

πŸ‘‰ https://hackerone.com/reports/881901

πŸ”Ή Severity: High | πŸ’° 10,000 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #r0hack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 1:19pm (UTC)
REFLECTED XSS On http://jsgames.mail.ru/bad_browser.php via back_url paramter

πŸ‘‰ https://hackerone.com/reports/948259

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #yukusawa18
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 1:23pm (UTC)
Reflected XSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/971360

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #nagli
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:20pm (UTC)
Elmah.axd is publicly accessible and leaking Error Log for ROOT on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ_PRD_WEB1 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆelmah.axd

πŸ‘‰ https://hackerone.com/reports/962753

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #rudra_2000
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:22pm (UTC)
CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.

πŸ‘‰ https://hackerone.com/reports/951508

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #professor1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:23pm (UTC)
β–ˆβ–ˆβ–ˆ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability

πŸ‘‰ https://hackerone.com/reports/959187

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #secret_letters
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:24pm (UTC)
Remote Code Execution on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/962013

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #hzllaga
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:25pm (UTC)