🎯 New Report #1544236: returnUrl= allow attacker to redirect users to the another phising website and takeover credientials
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
⏰ Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
⏰ Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports
🎯 New Report #1695604: DoS Vulnerability via Cache Poisoning on cdn.shopify.com and shopify-assets.shopifycdn.com
🔺Severity: Medium
👽 Reporter: bassem sadaqah
💼 Team: Shopify
💵 Bounty: 3800
🕐 Submitted: 2022-09-08
⏰ Disclosed: 2025-06-04 19:07:38
📝 Summary: There was a web cache poisoning vulnerability on Shopify's CDN domains that allowed an attacker to block access to any file hosted on the website. The vulnerability existed because the cache server treated backslashes and forward slashes as equivalent, while the origin server returned 404 errors for paths with backslashes. This discrepancy was exploited to cache 404 error pages for legitimate requests, causing a Denial of Service condition.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bassem sadaqah
💼 Team: Shopify
💵 Bounty: 3800
🕐 Submitted: 2022-09-08
⏰ Disclosed: 2025-06-04 19:07:38
📝 Summary: There was a web cache poisoning vulnerability on Shopify's CDN domains that allowed an attacker to block access to any file hosted on the website. The vulnerability existed because the cache server treated backslashes and forward slashes as equivalent, while the origin server returned 404 errors for paths with backslashes. This discrepancy was exploited to cache 404 error pages for legitimate requests, causing a Denial of Service condition.
@hackeronereports
🎯 New Report #3081691: 1 Click Account Takeover via Auth Token Theft on marketing.hostinger.com
🔺Severity: High
👽 Reporter: aziz0x48
💼 Team: hostinger
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-06-06 12:10:25
📝 Summary: The vulnerability discovered in the marketing.hostinger.com subdomain allowed for one-click account takeover through the theft of authentication tokens. An attacker could exploit the whitelisted redirect functionality of the subdomain to steal a victim's authentication token, which could then be used to gain full access to the victim's Hostinger account.
@hackeronereports
🔺Severity: High
👽 Reporter: aziz0x48
💼 Team: hostinger
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-06-06 12:10:25
📝 Summary: The vulnerability discovered in the marketing.hostinger.com subdomain allowed for one-click account takeover through the theft of authentication tokens. An attacker could exploit the whitelisted redirect functionality of the subdomain to steal a victim's authentication token, which could then be used to gain full access to the victim's Hostinger account.
@hackeronereports
❤2
🎯 New Report #3175928: ImageId Format Injection in Image Upload Endpoint
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-06-06 17:43:33
📝 Summary: The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId format.
@hackeronereports
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-06-06 17:43:33
📝 Summary: The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId format.
@hackeronereports
🎯 New Report #2633771: IDOR Vulnerability at AddTagToAssets operation name
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2024-07-31
⏰ Disclosed: 2025-06-08 16:28:23
📝 Summary: The IDOR vulnerability was discovered in the AddTagToAssets operation name of a GraphQL endpoint. The vulnerability allowed an attacker to obtain the IDs of custom tags created by a victim by decoding the base64-encoded tagId parameter in the request. This revealed the format and pattern of the tag IDs, enabling the attacker to perform a brute-force attack to disclose the victim's custom tags without any interaction with the victim.
@hackeronereports
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2024-07-31
⏰ Disclosed: 2025-06-08 16:28:23
📝 Summary: The IDOR vulnerability was discovered in the AddTagToAssets operation name of a GraphQL endpoint. The vulnerability allowed an attacker to obtain the IDs of custom tags created by a victim by decoding the base64-encoded tagId parameter in the request. This revealed the format and pattern of the tag IDs, enabling the attacker to perform a brute-force attack to disclose the victim's custom tags without any interaction with the victim.
@hackeronereports
🎯 New Report #3181066: Path Traversal Vulnerability in Lila Project
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🎯 New Report #2894018: Lack of Feedback Validation Permits Arbitrary Driver Ratings
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-12-10
⏰ Disclosed: 2025-06-12 13:26:15
📝 Summary: The vulnerability discovered by @bugbountywithmarco in Bykea's feedback system allowed authenticated passengers to submit feedback for drivers they had not actually ridden with. The exploit was limited to trips the attacker legitimately owned, and each trip could only affect one driver rating at a time. However, this flaw could still be abused to unfairly manipulate driver scores, undermining the reliability of the platform's reputation system.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-12-10
⏰ Disclosed: 2025-06-12 13:26:15
📝 Summary: The vulnerability discovered by @bugbountywithmarco in Bykea's feedback system allowed authenticated passengers to submit feedback for drivers they had not actually ridden with. The exploit was limited to trips the attacker legitimately owned, and each trip could only affect one driver rating at a time. However, this flaw could still be abused to unfairly manipulate driver scores, undermining the reliability of the platform's reputation system.
@hackeronereports
🎯 New Report #2489843: Crafted smart contract can take 1.5 minutes to execute due to inefficient CODESIZE implementation
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-05-03
⏰ Disclosed: 2025-06-12 18:52:48
📝 Summary: The crafted smart contract can take 1.5 minutes to execute due to an inefficient implementation of the CODESIZE operation in the VM. The issue was caused by the
@hackeronereports
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-05-03
⏰ Disclosed: 2025-06-12 18:52:48
📝 Summary: The crafted smart contract can take 1.5 minutes to execute due to an inefficient implementation of the CODESIZE operation in the VM. The issue was caused by the
VM.doCODESIZE() method, which retrieved the entire code array instead of just the code length. This behavior could be exploited to transfer large amounts of data, leading to a significant slowdown in contract execution.@hackeronereports
🔥1
🎯 New Report #2559404: Crafted smart contract can take ~23 seconds to execute due to immense error string construction
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-06-18
⏰ Disclosed: 2025-06-12 18:52:17
📝 Summary: The crafted smart contract can take approximately 23 seconds to execute due to the immense error string construction. The vulnerability was caused by the native contract's implementation, which constructed the entirety of the input message as a hex string for logging and throwing an exception. This approach resulted in a significantly longer execution time when provided with a large, invalid input.
@hackeronereports
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-06-18
⏰ Disclosed: 2025-06-12 18:52:17
📝 Summary: The crafted smart contract can take approximately 23 seconds to execute due to the immense error string construction. The vulnerability was caused by the native contract's implementation, which constructed the entirety of the input message as a hex string for logging and throwing an exception. This approach resulted in a significantly longer execution time when provided with a large, invalid input.
@hackeronereports
🔥1
🎯 New Report #3146996: [XSS Reflected XSS via POST request in (███████)](https://hackerone.com/reports/3146996)
🔺Severity: Medium
👽 Reporter: morphykutay
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-14
⏰ Disclosed: 2025-06-12 20:24:38
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the celular parameter of a POST request to the homepage of a Mars-owned website. The vulnerability was classified as medium severity with a CVSS score of 6.2. The application failed to properly sanitize user input before rendering it in the response, which allowed arbitrary JavaScript code to be executed in the victim's browser context. The vulnerability was initially reported on May 14, 2025 and was subsequently verified by the security team. After remediation efforts, the issue was confirmed as resolved on June 11, 2025. The vulnerability fell under CWE-79 (Improper Neutralization of Input During Web Page Generation).
@hackeronereports
🔺Severity: Medium
👽 Reporter: morphykutay
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-14
⏰ Disclosed: 2025-06-12 20:24:38
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the celular parameter of a POST request to the homepage of a Mars-owned website. The vulnerability was classified as medium severity with a CVSS score of 6.2. The application failed to properly sanitize user input before rendering it in the response, which allowed arbitrary JavaScript code to be executed in the victim's browser context. The vulnerability was initially reported on May 14, 2025 and was subsequently verified by the security team. After remediation efforts, the issue was confirmed as resolved on June 11, 2025. The vulnerability fell under CWE-79 (Improper Neutralization of Input During Web Page Generation).
@hackeronereports
🎯 New Report #2861888: Ability to increase any customer offered fare (BAC)
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-06-13 04:52:25
📝 Summary: A business logic flaw was discovered that allowed a malicious passenger or driver (acting as a passenger) to increase the fare of another customer's ride without their involvement. By chaining two unauthenticated endpoints, an attacker could cause an inflated fare to appear on the driver's screen.
@hackeronereports
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-06-13 04:52:25
📝 Summary: A business logic flaw was discovered that allowed a malicious passenger or driver (acting as a passenger) to increase the fare of another customer's ride without their involvement. By chaining two unauthenticated endpoints, an attacker could cause an inflated fare to appear on the driver's screen.
@hackeronereports
🎯 New Report #2374730: Broken Access Control (IDOR) in Booking Detail and Bids Could Leads to Sensitive Information Disclosure
🔺Severity: High
👽 Reporter: back2arie
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-02-15
⏰ Disclosed: 2025-06-13 04:36:06
📝 Summary: The report identified a vulnerability in the Bykea application's booking detail and bids endpoints that could lead to the disclosure of sensitive information. The vulnerable endpoints allowed an attacker to access the booking details, bids information, and bids configuration of other users by modifying the
@hackeronereports
🔺Severity: High
👽 Reporter: back2arie
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-02-15
⏰ Disclosed: 2025-06-13 04:36:06
📝 Summary: The report identified a vulnerability in the Bykea application's booking detail and bids endpoints that could lead to the disclosure of sensitive information. The vulnerable endpoints allowed an attacker to access the booking details, bids information, and bids configuration of other users by modifying the
booking id parameter in the request URL. This issue was classified as an Insecure Direct Object Reference (IDOR) vulnerability.@hackeronereports
🎯 New Report #3198394: WordPress Version Exposure via /wp-links-opml.php on hemi.xyz
🔺Severity: null
👽 Reporter: 1 ali raza
💼 Team: Hemi VDP
💵 Bounty: null
🕐 Submitted: 2025-06-12
⏰ Disclosed: 2025-06-13 04:18:35
📝 Summary: The WordPress CMS version was exposed in the XML file at https://hemi.xyz/wp-links-opml.php. This disclosure allowed attackers to identify the specific CMS version running on the site.
@hackeronereports
🔺Severity: null
👽 Reporter: 1 ali raza
💼 Team: Hemi VDP
💵 Bounty: null
🕐 Submitted: 2025-06-12
⏰ Disclosed: 2025-06-13 04:18:35
📝 Summary: The WordPress CMS version was exposed in the XML file at https://hemi.xyz/wp-links-opml.php. This disclosure allowed attackers to identify the specific CMS version running on the site.
@hackeronereports
🎯 New Report #3085742: IDOR on in-app hardcoded zombie endpoint
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-06-13 05:48:51
📝 Summary: The researcher discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible. By reverse engineering the Android app and reviewing the code for unused endpoints, the sensitive details related to drivers involved in other users' trips were leaked without validating trip ownership.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-06-13 05:48:51
📝 Summary: The researcher discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible. By reverse engineering the Android app and reviewing the code for unused endpoints, the sensitive details related to drivers involved in other users' trips were leaked without validating trip ownership.
@hackeronereports
🎯 New Report #2868164: Bypassing Bronze Partner Wallet Restriction to Accept Trips with Negative Balance
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-13 05:24:13
📝 Summary: The vulnerability allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints, a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-13 05:24:13
📝 Summary: The vulnerability allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints, a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.
@hackeronereports
🎯 New Report #3160210: Improper Authentication Throttling Allows Attacker-Controlled Account Lockouts
🔺Severity: Medium
👽 Reporter: closec4ll
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-23
⏰ Disclosed: 2025-06-13 06:25:39
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: closec4ll
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-23
⏰ Disclosed: 2025-06-13 06:25:39
📝 Summary: null
@hackeronereports
🎯 New Report #2105808: DOS of RSKJ server
🔺Severity: High
👽 Reporter: spacewasp
💼 Team: Rootstock Labs
💵 Bounty: 5000
🕐 Submitted: 2023-08-10
⏰ Disclosed: 2025-06-13 14:23:25
📝 Summary: The RSKJ server was vulnerable to a Denial of Service (DoS) attack. The vulnerability was due to a flaw in the RLP (Recursive Length Prefix) decoding function, which could return a negative value, leading to a length of 0. This caused the server to process only one UDP packet forever, preventing it from processing other incoming packets. The vulnerability could cause the server to crash due to Out of Memory issues.
@hackeronereports
🔺Severity: High
👽 Reporter: spacewasp
💼 Team: Rootstock Labs
💵 Bounty: 5000
🕐 Submitted: 2023-08-10
⏰ Disclosed: 2025-06-13 14:23:25
📝 Summary: The RSKJ server was vulnerable to a Denial of Service (DoS) attack. The vulnerability was due to a flaw in the RLP (Recursive Length Prefix) decoding function, which could return a negative value, leading to a length of 0. This caused the server to process only one UDP packet forever, preventing it from processing other incoming packets. The vulnerability could cause the server to crash due to Out of Memory issues.
@hackeronereports
🎯 New Report #2412583: Crafted smart contract can take 8 minutes to execute due to bug in modexp precompile.
🔺Severity: High
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-03-11
⏰ Disclosed: 2025-06-13 17:02:36
📝 Summary: A bug in the modexp precompile of an Ethereum-based blockchain can cause long stalls in the execution of crafted smart contracts. The issue was reported and could have potentially stalled the network.
@hackeronereports
🔺Severity: High
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-03-11
⏰ Disclosed: 2025-06-13 17:02:36
📝 Summary: A bug in the modexp precompile of an Ethereum-based blockchain can cause long stalls in the execution of crafted smart contracts. The issue was reported and could have potentially stalled the network.
@hackeronereports
🎯 New Report #3096384: [20.98.103.245 Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal](https://hackerone.com/reports/3096384)
🔺Severity: High
👽 Reporter: xbow
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-06-13 18:35:09
📝 Summary: A Cross-Site Scripting (XSS) vulnerability was discovered in the GlobalProtect VPN portal's getconfig.esp endpoint. The vulnerability existed because the application reflected user input from the 'user' parameter in an XML response without proper sanitization. An attacker could have injected SVG elements with JavaScript event handlers that executed when the XML document was rendered in a browser.
@hackeronereports
🔺Severity: High
👽 Reporter: xbow
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-06-13 18:35:09
📝 Summary: A Cross-Site Scripting (XSS) vulnerability was discovered in the GlobalProtect VPN portal's getconfig.esp endpoint. The vulnerability existed because the application reflected user input from the 'user' parameter in an XML response without proper sanitization. An attacker could have injected SVG elements with JavaScript event handlers that executed when the XML document was rendered in a browser.
@hackeronereports
👾1
🎯 New Report #2054283: Improper HTTP header block termination in llhttp
🔺Severity: Medium
👽 Reporter: kenballus
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-07
⏰ Disclosed: 2025-06-13 21:37:06
📝 Summary: The vulnerability in Node.js 20's HTTP parser allowed improper termination of HTTP/1 headers using
@hackeronereports
🔺Severity: Medium
👽 Reporter: kenballus
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-07
⏰ Disclosed: 2025-06-13 21:37:06
📝 Summary: The vulnerability in Node.js 20's HTTP parser allowed improper termination of HTTP/1 headers using
\r\n\rX instead of the required \r\n\r\n. This inconsistency enabled request smuggling. The issue was resolved by upgrading llhttp to version 9, which enforces correct header termination.@hackeronereports
🎯 New Report #3129421: EXIF metadata not stripped from profile image
🔺Severity: Medium
👽 Reporter: growler09
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-05-06
⏰ Disclosed: 2025-06-18 09:46:25
📝 Summary: The EXIF metadata was not stripped from the profile images uploaded to the platform. This could have resulted in the disclosure of location or other personal information associated with the uploaded images.
@hackeronereports
🔺Severity: Medium
👽 Reporter: growler09
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-05-06
⏰ Disclosed: 2025-06-18 09:46:25
📝 Summary: The EXIF metadata was not stripped from the profile images uploaded to the platform. This could have resulted in the disclosure of location or other personal information associated with the uploaded images.
@hackeronereports