Email Confirmation Bypass in your-store.myshopify.com which leads to privilege escalation
π https://hackerone.com/reports/910300
πΉ Severity: Critical | π° 22,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #say_ch33se
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 6:47am (UTC)
π https://hackerone.com/reports/910300
πΉ Severity: Critical | π° 22,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #say_ch33se
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 6:47am (UTC)
CircleCI token in github repo allows for access to sensitive build information
π https://hackerone.com/reports/858915
πΉ Severity: No Rating | π° 1,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #dwimmerlaik
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 9:30am (UTC)
π https://hackerone.com/reports/858915
πΉ Severity: No Rating | π° 1,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #dwimmerlaik
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 9:30am (UTC)
[icq.im] Reflected XSS via chat invite link
π https://hackerone.com/reports/796897
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #romesful
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 12:25pm (UTC)
π https://hackerone.com/reports/796897
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #romesful
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 12:25pm (UTC)
Private files exposed to other apps
π https://hackerone.com/reports/838587
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:14pm (UTC)
π https://hackerone.com/reports/838587
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:14pm (UTC)
Database read through provider misconfiguration
π https://hackerone.com/reports/882475
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:20pm (UTC)
π https://hackerone.com/reports/882475
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:20pm (UTC)
IDOR in tracking driver logs at city-mobil.ru
π https://hackerone.com/reports/847876
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #r0hack
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:59pm (UTC)
π https://hackerone.com/reports/847876
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #r0hack
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:59pm (UTC)
Cache Poisoning via uppercase letters in invalid path
π https://hackerone.com/reports/960618
πΉ Severity: Medium | π° 550 USD
πΉ Reported To: InnoGames
πΉ Reported By: #mace
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 2:48pm (UTC)
π https://hackerone.com/reports/960618
πΉ Severity: Medium | π° 550 USD
πΉ Reported To: InnoGames
πΉ Reported By: #mace
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 2:48pm (UTC)
xss triggered in "myshopify.com/admin/product"
π https://hackerone.com/reports/978125
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 8:30pm (UTC)
π https://hackerone.com/reports/978125
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 8:30pm (UTC)
[authmagic-timerange-stateless-core] Improper Authentication
π https://hackerone.com/reports/736522
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ermilov
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 5:07am (UTC)
π https://hackerone.com/reports/736522
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ermilov
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 5:07am (UTC)
Possible denial of service when entering a loooong password
π https://hackerone.com/reports/952349
πΉ Severity: Medium
πΉ Reported To: Nextcloud
πΉ Reported By: #guoxuxin
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 9:28am (UTC)
π https://hackerone.com/reports/952349
πΉ Severity: Medium
πΉ Reported To: Nextcloud
πΉ Reported By: #guoxuxin
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 9:28am (UTC)
Clear text storage of proxy parameters and passwords
π https://hackerone.com/reports/685990
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #rbcafe
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 2:32pm (UTC)
π https://hackerone.com/reports/685990
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #rbcafe
πΉ State: π’ Resolved
πΉ Disclosed: September 16, 2020, 2:32pm (UTC)
IDOR - User is able to download charts/dashboards from cross accounts
π https://hackerone.com/reports/975749
πΉ Severity: No Rating
πΉ Reported To: New Relic
πΉ Reported By: #k3ne
πΉ State: π΄ N/A
πΉ Disclosed: September 17, 2020, 11:24am (UTC)
π https://hackerone.com/reports/975749
πΉ Severity: No Rating
πΉ Reported To: New Relic
πΉ Reported By: #k3ne
πΉ State: π΄ N/A
πΉ Disclosed: September 17, 2020, 11:24am (UTC)
Self XSS
π https://hackerone.com/reports/982510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #wannacry0x01
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 4:07pm (UTC)
π https://hackerone.com/reports/982510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #wannacry0x01
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 4:07pm (UTC)
email spoofing
π https://hackerone.com/reports/981456
πΉ Severity: Medium
πΉ Reported To: Solana BBP
πΉ Reported By: #crazy_criminal_bj-4545
πΉ State: π€ Duplicate
πΉ Disclosed: September 17, 2020, 9:59pm (UTC)
π https://hackerone.com/reports/981456
πΉ Severity: Medium
πΉ Reported To: Solana BBP
πΉ Reported By: #crazy_criminal_bj-4545
πΉ State: π€ Duplicate
πΉ Disclosed: September 17, 2020, 9:59pm (UTC)
[@knutkirkhorn/free-space] - Command Injection through Lack of Sanitization
π https://hackerone.com/reports/950192
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ansuj
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 12:35pm (UTC)
π https://hackerone.com/reports/950192
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ansuj
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 12:35pm (UTC)
Log files Leaked In mcsblog.ru
π https://hackerone.com/reports/909166
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #sniper302
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:25pm (UTC)
π https://hackerone.com/reports/909166
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #sniper302
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:25pm (UTC)
Broken twitter link hijacking at https://games.mail.ru/pc/search/
π https://hackerone.com/reports/975653
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #nagli
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:30pm (UTC)
π https://hackerone.com/reports/975653
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #nagli
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:30pm (UTC)
Java : add MongoDB injection sinks
π https://hackerone.com/reports/983867
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #porcupineyhairs
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 7:30pm (UTC)
π https://hackerone.com/reports/983867
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #porcupineyhairs
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 7:30pm (UTC)
Stored XSS in collabora via user name
π https://hackerone.com/reports/968232
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #meliodas19
πΉ State: π’ Resolved
πΉ Disclosed: September 19, 2020, 2:00am (UTC)
π https://hackerone.com/reports/968232
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #meliodas19
πΉ State: π’ Resolved
πΉ Disclosed: September 19, 2020, 2:00am (UTC)
Buffer over read from `smtp_command_parse_parameters`
π https://hackerone.com/reports/900548
πΉ Severity: No Rating | π° 50 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #catenacyber
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 9:15am (UTC)
π https://hackerone.com/reports/900548
πΉ Severity: No Rating | π° 50 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #catenacyber
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 9:15am (UTC)
Sensitive information about a ββββββ
π https://hackerone.com/reports/893970
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x9747
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:49pm (UTC)
π https://hackerone.com/reports/893970
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x9747
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:49pm (UTC)