Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
SQL injection at fleet.city-mobil.ru

πŸ‘‰ https://hackerone.com/reports/881901

πŸ”Ή Severity: High | πŸ’° 10,000 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #r0hack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 1:19pm (UTC)
REFLECTED XSS On http://jsgames.mail.ru/bad_browser.php via back_url paramter

πŸ‘‰ https://hackerone.com/reports/948259

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #yukusawa18
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 1:23pm (UTC)
Reflected XSS on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/971360

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #nagli
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:20pm (UTC)
Elmah.axd is publicly accessible and leaking Error Log for ROOT on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ_PRD_WEB1 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆelmah.axd

πŸ‘‰ https://hackerone.com/reports/962753

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #rudra_2000
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:22pm (UTC)
CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.

πŸ‘‰ https://hackerone.com/reports/951508

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #professor1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:23pm (UTC)
β–ˆβ–ˆβ–ˆ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability

πŸ‘‰ https://hackerone.com/reports/959187

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #secret_letters
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:24pm (UTC)
Remote Code Execution on β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/962013

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #hzllaga
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:25pm (UTC)
Π‘ode injection host β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/954398

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #e3xpl0it
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:27pm (UTC)
Subdomain takeover due to an unclaimed Amazon S3 bucket on β–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/918946

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #chron0x
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 5:29pm (UTC)
Local Privilege Escalation on Dropbox Desktop for Windows

πŸ‘‰ https://hackerone.com/reports/773571

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Dropbox
πŸ”Ή Reported By: #tesitura
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: September 3, 2020, 6:50pm (UTC)
Cross-origin resource sharing misconfiguration (CORS)

πŸ‘‰ https://hackerone.com/reports/954512

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Brave Software
πŸ”Ή Reported By: #drwx
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 4, 2020, 12:34am (UTC)
CodeQL query to detect XSLT injections

πŸ‘‰ https://hackerone.com/reports/974368

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #grzegol
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 9:56pm (UTC)
[CATENACYBER]: [CPP] CWE-476 Null Pointer Dereference : Another query to either missing or redundant NULL check

πŸ‘‰ https://hackerone.com/reports/974370

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 9:56pm (UTC)
Query to find TLS configurations supporting hardcoded insecure versions of the protocol and cipher suites

πŸ‘‰ https://hackerone.com/reports/974369

πŸ”Ή Severity: High | πŸ’° 2,300 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #logicmap
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2020, 9:56pm (UTC)
[NR Synthetics] Restricted User can add/modify alert conditions on monitors without any synthetics privileges

πŸ‘‰ https://hackerone.com/reports/334143

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:54am (UTC)
User is able to access and create private synthetics locations without upgrading (regression of #276157)

πŸ‘‰ https://hackerone.com/reports/344468

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:55am (UTC)
IDOR via internal_api "users" endpoint

πŸ‘‰ https://hackerone.com/reports/349291

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:55am (UTC)
[NR Insights] Data app permissions setting does not fully prevent other users from modifying/changing changing data related to your data app

πŸ‘‰ https://hackerone.com/reports/388743

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:56am (UTC)
[NR Infrastructure] Restricted user can update integration provider account name via integrations API

πŸ‘‰ https://hackerone.com/reports/397483

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:57am (UTC)
Permissions leaks the full name of other NR accounts - Regression of #267636

πŸ‘‰ https://hackerone.com/reports/347665

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:58am (UTC)
[NR Alerts] Internal API exposes Synthetics monitor details to a restricted user without view monitor permissions

πŸ‘‰ https://hackerone.com/reports/386556

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2020, 10:58am (UTC)