Bugpoint
999 subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Keychain data persistence may lead to account takeover

πŸ‘‰ https://hackerone.com/reports/761975

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: QIWI
πŸ”Ή Reported By: #0x3c3e
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2020, 2:47pm (UTC)
XSS on https://fax.pbx.itsendless.org/ (CVE-2017-18024)

πŸ‘‰ https://hackerone.com/reports/963798

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Endless Hosting
πŸ”Ή Reported By: #pirneci
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2020, 5:42pm (UTC)
[bugs.fuzzing-project.org] HTML Injection via 'custom_field_7[]' parameter in '/view_all_set.php'

πŸ‘‰ https://hackerone.com/reports/903869

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Hanno's projects
πŸ”Ή Reported By: #dragonjar
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 7:30am (UTC)
No CSRF Protection in Resend Confirmation Email feature leads to Sending Unwanted Email in Victim's Inbox without knowing Victim's email address

πŸ‘‰ https://hackerone.com/reports/753386

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Stripo Inc
πŸ”Ή Reported By: #binit
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 11:17am (UTC)
SSRF into Shared Runner, by replacing dockerd with malicious server in Executor

πŸ‘‰ https://hackerone.com/reports/809248

πŸ”Ή Severity: Medium | πŸ’° 2,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #lucash-dev
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 1:28pm (UTC)
Members from parent group keep their access level on a subgroup transfer and are invisible

πŸ‘‰ https://hackerone.com/reports/790786

πŸ”Ή Severity: High | πŸ’° 4,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #kryword
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 1:44pm (UTC)
Injection of `http.<url>.*` git config settings leading to SSRF

πŸ‘‰ https://hackerone.com/reports/855276

πŸ”Ή Severity: High | πŸ’° 3,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #vakzz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 1:46pm (UTC)
EXIF metadata not stripped from JPG group logos

πŸ‘‰ https://hackerone.com/reports/446238

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #jackb898
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 2:02pm (UTC)
Blind SQL Injection

πŸ‘‰ https://hackerone.com/reports/758654

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: InnoGames
πŸ”Ή Reported By: #rzx007x
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2020, 3:04pm (UTC)
Race Condition when following a user

πŸ‘‰ https://hackerone.com/reports/927384

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Staging.every.org
πŸ”Ή Reported By: #bugra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 5:51am (UTC)
damage to the timeline so that comment fields cannot be displayed or not available to all members in the store

πŸ‘‰ https://hackerone.com/reports/971599

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #jaka_tingkir
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 4:45pm (UTC)
Add apps to packages 0, 61, 62 with /store/ajaxpackagemerge

πŸ‘‰ https://hackerone.com/reports/972243

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: Valve
πŸ”Ή Reported By: #njbooher
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 8:07pm (UTC)
Unauthorized updates to extended_info properties in /store/ajaxpackagesave

πŸ‘‰ https://hackerone.com/reports/815547

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: Valve
πŸ”Ή Reported By: #njbooher
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 8:27pm (UTC)
Stored XSS on PyPi simple API endpoint

πŸ‘‰ https://hackerone.com/reports/856836

πŸ”Ή Severity: Medium | πŸ’° 3,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #vakzz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 9:57pm (UTC)
Stored XSS in markdown when redacting references

πŸ‘‰ https://hackerone.com/reports/836649

πŸ”Ή Severity: High | πŸ’° 5,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #vakzz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 9:58pm (UTC)
Smartsheet employees email disclosure through enpoint after login.

πŸ‘‰ https://hackerone.com/reports/880089

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Smartsheet
πŸ”Ή Reported By: #soareswallace
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2020, 10:15pm (UTC)
SSRF at https://cognitive.topcoder.com leads to AWS instance metadata due to vulnerable email subscription feature

πŸ‘‰ https://hackerone.com/reports/876424

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: Topcoder
πŸ”Ή Reported By: #mase289
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2020, 12:42pm (UTC)
THX Tuneup Survey feedback disclosure via Google cached content for apps.thx.com

πŸ‘‰ https://hackerone.com/reports/751729

πŸ”Ή Severity: Low | πŸ’° 200 USD
πŸ”Ή Reported To: Razer
πŸ”Ή Reported By: #jackb898
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2020, 4:04pm (UTC)
bypass the [OKTA] login redirect can lead to disclosing limited-information about the sub-domain at [ shiptsec.com ]

πŸ‘‰ https://hackerone.com/reports/968699

πŸ”Ή Severity: Low | πŸ’° 200 USD
πŸ”Ή Reported To: Shipt
πŸ”Ή Reported By: #tester1231233
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2020, 4:23pm (UTC)
Safe Redirect Bypass

πŸ‘‰ https://hackerone.com/reports/945990

πŸ”Ή Severity: Low | πŸ’° 560 USD
πŸ”Ή Reported To: Twitter
πŸ”Ή Reported By: #cyanpiny
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2020, 4:57pm (UTC)
Team object in GraphQL disclosed private_comment

πŸ‘‰ https://hackerone.com/reports/978143

πŸ”Ή Severity: Medium | πŸ’° 2,500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #haxta4ok00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2020, 7:05pm (UTC)