Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Log files Leaked In mcsblog.ru

πŸ‘‰ https://hackerone.com/reports/909166

πŸ”Ή Severity: Medium | πŸ’° 150 USD
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #sniper302
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 18, 2020, 3:25pm (UTC)
Broken twitter link hijacking at https://games.mail.ru/pc/search/

πŸ‘‰ https://hackerone.com/reports/975653

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Mail.ru
πŸ”Ή Reported By: #nagli
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 18, 2020, 3:30pm (UTC)
Java : add MongoDB injection sinks

πŸ‘‰ https://hackerone.com/reports/983867

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #porcupineyhairs
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 17, 2020, 7:30pm (UTC)
Stored XSS in collabora via user name

πŸ‘‰ https://hackerone.com/reports/968232

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #meliodas19
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 19, 2020, 2:00am (UTC)
Buffer over read from `smtp_command_parse_parameters`

πŸ‘‰ https://hackerone.com/reports/900548

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2020, 9:15am (UTC)
Sensitive information about a β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/893970

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0x9747
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2020, 2:49pm (UTC)
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion

πŸ‘‰ https://hackerone.com/reports/960330

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #oucast-
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2020, 2:50pm (UTC)
Reflected Xss

πŸ‘‰ https://hackerone.com/reports/758854

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0xelkomy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2020, 2:52pm (UTC)
DOM Based XSS at docs.8x8.com

πŸ‘‰ https://hackerone.com/reports/895917

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #wh0ru
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2020, 3:07pm (UTC)
"Basic user" which can only access a limited subset of the platform can access certain pages which are restricted to the user by the account owner.

πŸ‘‰ https://hackerone.com/reports/966531

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jhimansh
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 22, 2020, 4:33pm (UTC)
[Half-Life 1] Malformed map name leads to memory corruption and code execution

πŸ‘‰ https://hackerone.com/reports/402566

πŸ”Ή Severity: High | πŸ’° 1,500 USD
πŸ”Ή Reported To: Valve
πŸ”Ή Reported By: #kbeckmann
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2020, 5:28pm (UTC)
[steam client] Opening a specific steam:// url overwrites files at an arbitrary location

πŸ‘‰ https://hackerone.com/reports/667242

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: Valve
πŸ”Ή Reported By: #kbeckmann
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2020, 6:48pm (UTC)
Public and secret api key leaked via Solana BBP github repo

πŸ‘‰ https://hackerone.com/reports/987084

πŸ”Ή Severity: High
πŸ”Ή Reported To: Solana BBP
πŸ”Ή Reported By: #0x4_aulia
πŸ”Ή State: 🟀 Duplicate
πŸ”Ή Disclosed: September 22, 2020, 6:57pm (UTC)
Stored-Xss at connect.topcoder.com/projects/ affected on project chat members

πŸ‘‰ https://hackerone.com/reports/779908

πŸ”Ή Severity: High
πŸ”Ή Reported To: Topcoder
πŸ”Ή Reported By: #sodium_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2020, 7:41pm (UTC)
China - IDOR on Reservation Staging/Non Production Site - https://reservation.stg.starbucks.com.cn

πŸ‘‰ https://hackerone.com/reports/715054

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Starbucks
πŸ”Ή Reported By: #xmfc
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2020, 9:04pm (UTC)
property-expr - Prototype pollution

πŸ‘‰ https://hackerone.com/reports/910206

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #ahihi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 4:00am (UTC)
Bypassing Business ID/VAT # validation during registration to create accounts with duplicate Business ID/VAT #

πŸ‘‰ https://hackerone.com/reports/980898

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #zeop
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 4:04pm (UTC)
[git-lib] RCE via insecure command formatting

πŸ‘‰ https://hackerone.com/reports/718241

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #mik317
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 4:17pm (UTC)
[hnzserver] Path Traversal allowing to read any files on the server

πŸ‘‰ https://hackerone.com/reports/579517

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #lightangel1412
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 7:08pm (UTC)
Android WebViews in Twitter app are vulnerable to UXSS due to configuration and CVE-2020-6506

πŸ‘‰ https://hackerone.com/reports/906433

πŸ”Ή Severity: High | πŸ’° 560 USD
πŸ”Ή Reported To: Twitter
πŸ”Ή Reported By: #alesandroortiz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 7:11pm (UTC)
[http_server] Path Traversal allowing to read any files on the server

πŸ‘‰ https://hackerone.com/reports/579523

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #lightangel1412
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 24, 2020, 7:21pm (UTC)