🎯 New Report #3181066: Path Traversal Vulnerability in Lila Project
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🎯 New Report #2894018: Lack of Feedback Validation Permits Arbitrary Driver Ratings
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-12-10
⏰ Disclosed: 2025-06-12 13:26:15
📝 Summary: The vulnerability discovered by @bugbountywithmarco in Bykea's feedback system allowed authenticated passengers to submit feedback for drivers they had not actually ridden with. The exploit was limited to trips the attacker legitimately owned, and each trip could only affect one driver rating at a time. However, this flaw could still be abused to unfairly manipulate driver scores, undermining the reliability of the platform's reputation system.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-12-10
⏰ Disclosed: 2025-06-12 13:26:15
📝 Summary: The vulnerability discovered by @bugbountywithmarco in Bykea's feedback system allowed authenticated passengers to submit feedback for drivers they had not actually ridden with. The exploit was limited to trips the attacker legitimately owned, and each trip could only affect one driver rating at a time. However, this flaw could still be abused to unfairly manipulate driver scores, undermining the reliability of the platform's reputation system.
@hackeronereports
🎯 New Report #2489843: Crafted smart contract can take 1.5 minutes to execute due to inefficient CODESIZE implementation
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-05-03
⏰ Disclosed: 2025-06-12 18:52:48
📝 Summary: The crafted smart contract can take 1.5 minutes to execute due to an inefficient implementation of the CODESIZE operation in the VM. The issue was caused by the
@hackeronereports
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-05-03
⏰ Disclosed: 2025-06-12 18:52:48
📝 Summary: The crafted smart contract can take 1.5 minutes to execute due to an inefficient implementation of the CODESIZE operation in the VM. The issue was caused by the
VM.doCODESIZE() method, which retrieved the entire code array instead of just the code length. This behavior could be exploited to transfer large amounts of data, leading to a significant slowdown in contract execution.@hackeronereports
🔥1
🎯 New Report #2559404: Crafted smart contract can take ~23 seconds to execute due to immense error string construction
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-06-18
⏰ Disclosed: 2025-06-12 18:52:17
📝 Summary: The crafted smart contract can take approximately 23 seconds to execute due to the immense error string construction. The vulnerability was caused by the native contract's implementation, which constructed the entirety of the input message as a hex string for logging and throwing an exception. This approach resulted in a significantly longer execution time when provided with a large, invalid input.
@hackeronereports
🔺Severity: Medium
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-06-18
⏰ Disclosed: 2025-06-12 18:52:17
📝 Summary: The crafted smart contract can take approximately 23 seconds to execute due to the immense error string construction. The vulnerability was caused by the native contract's implementation, which constructed the entirety of the input message as a hex string for logging and throwing an exception. This approach resulted in a significantly longer execution time when provided with a large, invalid input.
@hackeronereports
🔥1
🎯 New Report #3146996: [XSS Reflected XSS via POST request in (███████)](https://hackerone.com/reports/3146996)
🔺Severity: Medium
👽 Reporter: morphykutay
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-14
⏰ Disclosed: 2025-06-12 20:24:38
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the celular parameter of a POST request to the homepage of a Mars-owned website. The vulnerability was classified as medium severity with a CVSS score of 6.2. The application failed to properly sanitize user input before rendering it in the response, which allowed arbitrary JavaScript code to be executed in the victim's browser context. The vulnerability was initially reported on May 14, 2025 and was subsequently verified by the security team. After remediation efforts, the issue was confirmed as resolved on June 11, 2025. The vulnerability fell under CWE-79 (Improper Neutralization of Input During Web Page Generation).
@hackeronereports
🔺Severity: Medium
👽 Reporter: morphykutay
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-05-14
⏰ Disclosed: 2025-06-12 20:24:38
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was identified in the celular parameter of a POST request to the homepage of a Mars-owned website. The vulnerability was classified as medium severity with a CVSS score of 6.2. The application failed to properly sanitize user input before rendering it in the response, which allowed arbitrary JavaScript code to be executed in the victim's browser context. The vulnerability was initially reported on May 14, 2025 and was subsequently verified by the security team. After remediation efforts, the issue was confirmed as resolved on June 11, 2025. The vulnerability fell under CWE-79 (Improper Neutralization of Input During Web Page Generation).
@hackeronereports
🎯 New Report #2861888: Ability to increase any customer offered fare (BAC)
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-06-13 04:52:25
📝 Summary: A business logic flaw was discovered that allowed a malicious passenger or driver (acting as a passenger) to increase the fare of another customer's ride without their involvement. By chaining two unauthenticated endpoints, an attacker could cause an inflated fare to appear on the driver's screen.
@hackeronereports
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-06-13 04:52:25
📝 Summary: A business logic flaw was discovered that allowed a malicious passenger or driver (acting as a passenger) to increase the fare of another customer's ride without their involvement. By chaining two unauthenticated endpoints, an attacker could cause an inflated fare to appear on the driver's screen.
@hackeronereports
🎯 New Report #2374730: Broken Access Control (IDOR) in Booking Detail and Bids Could Leads to Sensitive Information Disclosure
🔺Severity: High
👽 Reporter: back2arie
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-02-15
⏰ Disclosed: 2025-06-13 04:36:06
📝 Summary: The report identified a vulnerability in the Bykea application's booking detail and bids endpoints that could lead to the disclosure of sensitive information. The vulnerable endpoints allowed an attacker to access the booking details, bids information, and bids configuration of other users by modifying the
@hackeronereports
🔺Severity: High
👽 Reporter: back2arie
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-02-15
⏰ Disclosed: 2025-06-13 04:36:06
📝 Summary: The report identified a vulnerability in the Bykea application's booking detail and bids endpoints that could lead to the disclosure of sensitive information. The vulnerable endpoints allowed an attacker to access the booking details, bids information, and bids configuration of other users by modifying the
booking id parameter in the request URL. This issue was classified as an Insecure Direct Object Reference (IDOR) vulnerability.@hackeronereports
🎯 New Report #3198394: WordPress Version Exposure via /wp-links-opml.php on hemi.xyz
🔺Severity: null
👽 Reporter: 1 ali raza
💼 Team: Hemi VDP
💵 Bounty: null
🕐 Submitted: 2025-06-12
⏰ Disclosed: 2025-06-13 04:18:35
📝 Summary: The WordPress CMS version was exposed in the XML file at https://hemi.xyz/wp-links-opml.php. This disclosure allowed attackers to identify the specific CMS version running on the site.
@hackeronereports
🔺Severity: null
👽 Reporter: 1 ali raza
💼 Team: Hemi VDP
💵 Bounty: null
🕐 Submitted: 2025-06-12
⏰ Disclosed: 2025-06-13 04:18:35
📝 Summary: The WordPress CMS version was exposed in the XML file at https://hemi.xyz/wp-links-opml.php. This disclosure allowed attackers to identify the specific CMS version running on the site.
@hackeronereports
🎯 New Report #3085742: IDOR on in-app hardcoded zombie endpoint
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-06-13 05:48:51
📝 Summary: The researcher discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible. By reverse engineering the Android app and reviewing the code for unused endpoints, the sensitive details related to drivers involved in other users' trips were leaked without validating trip ownership.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-04-09
⏰ Disclosed: 2025-06-13 05:48:51
📝 Summary: The researcher discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible. By reverse engineering the Android app and reviewing the code for unused endpoints, the sensitive details related to drivers involved in other users' trips were leaked without validating trip ownership.
@hackeronereports
🎯 New Report #2868164: Bypassing Bronze Partner Wallet Restriction to Accept Trips with Negative Balance
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-13 05:24:13
📝 Summary: The vulnerability allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints, a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bugbountywithmarco
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-13 05:24:13
📝 Summary: The vulnerability allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints, a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.
@hackeronereports
🎯 New Report #3160210: Improper Authentication Throttling Allows Attacker-Controlled Account Lockouts
🔺Severity: Medium
👽 Reporter: closec4ll
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-23
⏰ Disclosed: 2025-06-13 06:25:39
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: closec4ll
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-23
⏰ Disclosed: 2025-06-13 06:25:39
📝 Summary: null
@hackeronereports
🎯 New Report #2105808: DOS of RSKJ server
🔺Severity: High
👽 Reporter: spacewasp
💼 Team: Rootstock Labs
💵 Bounty: 5000
🕐 Submitted: 2023-08-10
⏰ Disclosed: 2025-06-13 14:23:25
📝 Summary: The RSKJ server was vulnerable to a Denial of Service (DoS) attack. The vulnerability was due to a flaw in the RLP (Recursive Length Prefix) decoding function, which could return a negative value, leading to a length of 0. This caused the server to process only one UDP packet forever, preventing it from processing other incoming packets. The vulnerability could cause the server to crash due to Out of Memory issues.
@hackeronereports
🔺Severity: High
👽 Reporter: spacewasp
💼 Team: Rootstock Labs
💵 Bounty: 5000
🕐 Submitted: 2023-08-10
⏰ Disclosed: 2025-06-13 14:23:25
📝 Summary: The RSKJ server was vulnerable to a Denial of Service (DoS) attack. The vulnerability was due to a flaw in the RLP (Recursive Length Prefix) decoding function, which could return a negative value, leading to a length of 0. This caused the server to process only one UDP packet forever, preventing it from processing other incoming packets. The vulnerability could cause the server to crash due to Out of Memory issues.
@hackeronereports
🎯 New Report #2412583: Crafted smart contract can take 8 minutes to execute due to bug in modexp precompile.
🔺Severity: High
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-03-11
⏰ Disclosed: 2025-06-13 17:02:36
📝 Summary: A bug in the modexp precompile of an Ethereum-based blockchain can cause long stalls in the execution of crafted smart contracts. The issue was reported and could have potentially stalled the network.
@hackeronereports
🔺Severity: High
👽 Reporter: guido
💼 Team: Rootstock Labs
💵 Bounty: null
🕐 Submitted: 2024-03-11
⏰ Disclosed: 2025-06-13 17:02:36
📝 Summary: A bug in the modexp precompile of an Ethereum-based blockchain can cause long stalls in the execution of crafted smart contracts. The issue was reported and could have potentially stalled the network.
@hackeronereports
🎯 New Report #3096384: [20.98.103.245 Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal](https://hackerone.com/reports/3096384)
🔺Severity: High
👽 Reporter: xbow
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-06-13 18:35:09
📝 Summary: A Cross-Site Scripting (XSS) vulnerability was discovered in the GlobalProtect VPN portal's getconfig.esp endpoint. The vulnerability existed because the application reflected user input from the 'user' parameter in an XML response without proper sanitization. An attacker could have injected SVG elements with JavaScript event handlers that executed when the XML document was rendered in a browser.
@hackeronereports
🔺Severity: High
👽 Reporter: xbow
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-04-16
⏰ Disclosed: 2025-06-13 18:35:09
📝 Summary: A Cross-Site Scripting (XSS) vulnerability was discovered in the GlobalProtect VPN portal's getconfig.esp endpoint. The vulnerability existed because the application reflected user input from the 'user' parameter in an XML response without proper sanitization. An attacker could have injected SVG elements with JavaScript event handlers that executed when the XML document was rendered in a browser.
@hackeronereports
👾1
🎯 New Report #2054283: Improper HTTP header block termination in llhttp
🔺Severity: Medium
👽 Reporter: kenballus
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-07
⏰ Disclosed: 2025-06-13 21:37:06
📝 Summary: The vulnerability in Node.js 20's HTTP parser allowed improper termination of HTTP/1 headers using
@hackeronereports
🔺Severity: Medium
👽 Reporter: kenballus
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-07
⏰ Disclosed: 2025-06-13 21:37:06
📝 Summary: The vulnerability in Node.js 20's HTTP parser allowed improper termination of HTTP/1 headers using
\r\n\rX instead of the required \r\n\r\n. This inconsistency enabled request smuggling. The issue was resolved by upgrading llhttp to version 9, which enforces correct header termination.@hackeronereports
🎯 New Report #3129421: EXIF metadata not stripped from profile image
🔺Severity: Medium
👽 Reporter: growler09
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-05-06
⏰ Disclosed: 2025-06-18 09:46:25
📝 Summary: The EXIF metadata was not stripped from the profile images uploaded to the platform. This could have resulted in the disclosure of location or other personal information associated with the uploaded images.
@hackeronereports
🔺Severity: Medium
👽 Reporter: growler09
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-05-06
⏰ Disclosed: 2025-06-18 09:46:25
📝 Summary: The EXIF metadata was not stripped from the profile images uploaded to the platform. This could have resulted in the disclosure of location or other personal information associated with the uploaded images.
@hackeronereports
🎯 New Report #3211126: Sensitive information disclosure with malicious netrc file
🔺Severity: Medium
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-06-22 10:55:55
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-06-22 10:55:55
📝 Summary: null
@hackeronereports
👍1
🎯 New Report #3211973: Credential leak on redirect due to improper state clearing when parsing macdef in netrc.c
🔺Severity: Low
👽 Reporter: oxghostly
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-20
⏰ Disclosed: 2025-06-22 16:26:30
📝 Summary: null
@hackeronereports
🔺Severity: Low
👽 Reporter: oxghostly
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-20
⏰ Disclosed: 2025-06-22 16:26:30
📝 Summary: null
@hackeronereports
🎯 New Report #3198980: Woocommerce SQL Injection in WC Report Coupon Usage
🔺Severity: Medium
👽 Reporter: q5ca
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2025-06-13
⏰ Disclosed: 2025-06-24 04:18:01
📝 Summary: A SQL injection vulnerability was found in the WooCommerce plugin version 9.9.3. The vulnerable parameter was 'coupon codes' in the '/wp-admin/admin.php?page=wc-reports
🔺Severity: Medium
👽 Reporter: q5ca
💼 Team: Automattic
💵 Bounty: null
🕐 Submitted: 2025-06-13
⏰ Disclosed: 2025-06-24 04:18:01
📝 Summary: A SQL injection vulnerability was found in the WooCommerce plugin version 9.9.3. The vulnerable parameter was 'coupon codes' in the '/wp-admin/admin.php?page=wc-reports
🎯 New Report #2209750: Exposed trip no in WebSocket Responses Leading to Excessive information Disclosure
🔺Severity: Medium
👽 Reporter: mrrhacker
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2023-10-15
⏰ Disclosed: 2025-06-26 10:13:41
📝 Summary: The vulnerability in Bykea's WebSocket implementation exposed the trip no identifier to drivers before a bid was accepted. This identifier could be used to access customer tracking URLs, revealing Personally Identifiable Information (PII) such as names, addresses, and contact details. The issue was resolved by masking sensitive identifiers in WebSocket responses and introducing hashing in tracking URLs to prevent unauthorized access.
@hackeronereports
🔺Severity: Medium
👽 Reporter: mrrhacker
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2023-10-15
⏰ Disclosed: 2025-06-26 10:13:41
📝 Summary: The vulnerability in Bykea's WebSocket implementation exposed the trip no identifier to drivers before a bid was accepted. This identifier could be used to access customer tracking URLs, revealing Personally Identifiable Information (PII) such as names, addresses, and contact details. The issue was resolved by masking sensitive identifiers in WebSocket responses and introducing hashing in tracking URLs to prevent unauthorized access.
@hackeronereports
🎯 New Report #2867022: Improper Access Control Allows Trip Hijacking and Passenger/Driver PII Disclosure
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-26 11:35:56
📝 Summary: The vulnerability discovered allowed improper access control, enabling an attacker to hijack trips and disclose passenger and driver personally identifiable information. The
@hackeronereports
🔺Severity: Medium
👽 Reporter: grassye
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2024-11-27
⏰ Disclosed: 2025-06-26 11:35:56
📝 Summary: The vulnerability discovered allowed improper access control, enabling an attacker to hijack trips and disclose passenger and driver personally identifiable information. The
/acknowledged the offer and /accept endpoints failed to properly validate the ownership of the trip id, allowing an attacker to substitute a victim's ID and force them into a ride or compel a driver to accept a trip they had cancelled or gone offline from.@hackeronereports
👀1