Log files Leaked In mcsblog.ru
π https://hackerone.com/reports/909166
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #sniper302
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:25pm (UTC)
π https://hackerone.com/reports/909166
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #sniper302
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:25pm (UTC)
Broken twitter link hijacking at https://games.mail.ru/pc/search/
π https://hackerone.com/reports/975653
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #nagli
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:30pm (UTC)
π https://hackerone.com/reports/975653
πΉ Severity: No Rating
πΉ Reported To: Mail.ru
πΉ Reported By: #nagli
πΉ State: π’ Resolved
πΉ Disclosed: September 18, 2020, 3:30pm (UTC)
Java : add MongoDB injection sinks
π https://hackerone.com/reports/983867
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #porcupineyhairs
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 7:30pm (UTC)
π https://hackerone.com/reports/983867
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #porcupineyhairs
πΉ State: π’ Resolved
πΉ Disclosed: September 17, 2020, 7:30pm (UTC)
Stored XSS in collabora via user name
π https://hackerone.com/reports/968232
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #meliodas19
πΉ State: π’ Resolved
πΉ Disclosed: September 19, 2020, 2:00am (UTC)
π https://hackerone.com/reports/968232
πΉ Severity: Low
πΉ Reported To: Nextcloud
πΉ Reported By: #meliodas19
πΉ State: π’ Resolved
πΉ Disclosed: September 19, 2020, 2:00am (UTC)
Buffer over read from `smtp_command_parse_parameters`
π https://hackerone.com/reports/900548
πΉ Severity: No Rating | π° 50 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #catenacyber
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 9:15am (UTC)
π https://hackerone.com/reports/900548
πΉ Severity: No Rating | π° 50 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #catenacyber
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 9:15am (UTC)
Sensitive information about a ββββββ
π https://hackerone.com/reports/893970
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x9747
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:49pm (UTC)
π https://hackerone.com/reports/893970
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0x9747
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:49pm (UTC)
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
π https://hackerone.com/reports/960330
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #oucast-
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:50pm (UTC)
π https://hackerone.com/reports/960330
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #oucast-
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:50pm (UTC)
Reflected Xss
π https://hackerone.com/reports/758854
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0xelkomy
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:52pm (UTC)
π https://hackerone.com/reports/758854
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #0xelkomy
πΉ State: π’ Resolved
πΉ Disclosed: September 21, 2020, 2:52pm (UTC)
DOM Based XSS at docs.8x8.com
π https://hackerone.com/reports/895917
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #wh0ru
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 3:07pm (UTC)
π https://hackerone.com/reports/895917
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #wh0ru
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 3:07pm (UTC)
"Basic user" which can only access a limited subset of the platform can access certain pages which are restricted to the user by the account owner.
π https://hackerone.com/reports/966531
πΉ Severity: No Rating
πΉ Reported To: New Relic
πΉ Reported By: #jhimansh
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 22, 2020, 4:33pm (UTC)
π https://hackerone.com/reports/966531
πΉ Severity: No Rating
πΉ Reported To: New Relic
πΉ Reported By: #jhimansh
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 22, 2020, 4:33pm (UTC)
[Half-Life 1] Malformed map name leads to memory corruption and code execution
π https://hackerone.com/reports/402566
πΉ Severity: High | π° 1,500 USD
πΉ Reported To: Valve
πΉ Reported By: #kbeckmann
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 5:28pm (UTC)
π https://hackerone.com/reports/402566
πΉ Severity: High | π° 1,500 USD
πΉ Reported To: Valve
πΉ Reported By: #kbeckmann
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 5:28pm (UTC)
[steam client] Opening a specific steam:// url overwrites files at an arbitrary location
π https://hackerone.com/reports/667242
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: Valve
πΉ Reported By: #kbeckmann
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 6:48pm (UTC)
π https://hackerone.com/reports/667242
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: Valve
πΉ Reported By: #kbeckmann
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 6:48pm (UTC)
Public and secret api key leaked via Solana BBP github repo
π https://hackerone.com/reports/987084
πΉ Severity: High
πΉ Reported To: Solana BBP
πΉ Reported By: #0x4_aulia
πΉ State: π€ Duplicate
πΉ Disclosed: September 22, 2020, 6:57pm (UTC)
π https://hackerone.com/reports/987084
πΉ Severity: High
πΉ Reported To: Solana BBP
πΉ Reported By: #0x4_aulia
πΉ State: π€ Duplicate
πΉ Disclosed: September 22, 2020, 6:57pm (UTC)
Stored-Xss at connect.topcoder.com/projects/ affected on project chat members
π https://hackerone.com/reports/779908
πΉ Severity: High
πΉ Reported To: Topcoder
πΉ Reported By: #sodium_
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 7:41pm (UTC)
π https://hackerone.com/reports/779908
πΉ Severity: High
πΉ Reported To: Topcoder
πΉ Reported By: #sodium_
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 7:41pm (UTC)
China - IDOR on Reservation Staging/Non Production Site - https://reservation.stg.starbucks.com.cn
π https://hackerone.com/reports/715054
πΉ Severity: Medium
πΉ Reported To: Starbucks
πΉ Reported By: #xmfc
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 9:04pm (UTC)
π https://hackerone.com/reports/715054
πΉ Severity: Medium
πΉ Reported To: Starbucks
πΉ Reported By: #xmfc
πΉ State: π’ Resolved
πΉ Disclosed: September 22, 2020, 9:04pm (UTC)
property-expr - Prototype pollution
π https://hackerone.com/reports/910206
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ahihi
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:00am (UTC)
π https://hackerone.com/reports/910206
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #ahihi
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:00am (UTC)
Bypassing Business ID/VAT # validation during registration to create accounts with duplicate Business ID/VAT #
π https://hackerone.com/reports/980898
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Visma Public
πΉ Reported By: #zeop
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:04pm (UTC)
π https://hackerone.com/reports/980898
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Visma Public
πΉ Reported By: #zeop
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:04pm (UTC)
[git-lib] RCE via insecure command formatting
π https://hackerone.com/reports/718241
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #mik317
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:17pm (UTC)
π https://hackerone.com/reports/718241
πΉ Severity: Medium
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #mik317
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 4:17pm (UTC)
[hnzserver] Path Traversal allowing to read any files on the server
π https://hackerone.com/reports/579517
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #lightangel1412
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:08pm (UTC)
π https://hackerone.com/reports/579517
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #lightangel1412
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:08pm (UTC)
Android WebViews in Twitter app are vulnerable to UXSS due to configuration and CVE-2020-6506
π https://hackerone.com/reports/906433
πΉ Severity: High | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #alesandroortiz
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:11pm (UTC)
π https://hackerone.com/reports/906433
πΉ Severity: High | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #alesandroortiz
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:11pm (UTC)
[http_server] Path Traversal allowing to read any files on the server
π https://hackerone.com/reports/579523
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #lightangel1412
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:21pm (UTC)
π https://hackerone.com/reports/579523
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #lightangel1412
πΉ State: π’ Resolved
πΉ Disclosed: September 24, 2020, 7:21pm (UTC)