🎯 New Report #3176157: DNS Rebinding SSRF in Burp Suite MCP Server Enables Internal Network Access via send http1 request Tool
🔺Severity: None
👽 Reporter: farmer
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: 2000
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-10-08 14:26:27
📝 Summary: The Burp Suite MCP (Model Context Protocol) server was vulnerable to a DNS rebinding attack. This allowed malicious websites to connect to the victim's local MCP server, use the send http1 request tool to make arbitrary HTTP requests, and access internal networks, localhost services, and cloud metadata endpoints. The vulnerability was caused by the lack of proper origin validation and CORS protection in the MCP server.
📂 Report JSON File: 3176157
@hackeronereports
🔺Severity: None
👽 Reporter: farmer
⭐️ Reputation: 114
🛠 State: resolved
💼 Team: PortSwigger Web Security
💵 Bounty: 2000
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-10-08 14:26:27
📝 Summary: The Burp Suite MCP (Model Context Protocol) server was vulnerable to a DNS rebinding attack. This allowed malicious websites to connect to the victim's local MCP server, use the send http1 request tool to make arbitrary HTTP requests, and access internal networks, localhost services, and cloud metadata endpoints. The vulnerability was caused by the lack of proper origin validation and CORS protection in the MCP server.
📂 Report JSON File: 3176157
@hackeronereports
🎯 New Report #3367292: CSRF allowing unauthorized modification of user Notes on ███████
🔺Severity: Low
👽 Reporter: kanon4
⭐️ Reputation: 742
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-10-10 18:37:09
📝 Summary: A CSRF vulnerability was discovered that allowed unauthorized modification of user notes. The vulnerability was present in the endpoint that handled saving the notes. The endpoint did not implement proper CSRF protection, allowing an attacker to craft a malicious link that could be used to modify or delete the victim's notes. The complexity of the attack was that the attacker needed to be a member of the same organization as the victim in order to obtain the victim's correct ID, which was required to carry out the attack.
📂 Report JSON File: 3367292
@hackeronereports
🔺Severity: Low
👽 Reporter: kanon4
⭐️ Reputation: 742
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-10-02
⏰ Disclosed: 2025-10-10 18:37:09
📝 Summary: A CSRF vulnerability was discovered that allowed unauthorized modification of user notes. The vulnerability was present in the endpoint that handled saving the notes. The endpoint did not implement proper CSRF protection, allowing an attacker to craft a malicious link that could be used to modify or delete the victim's notes. The complexity of the attack was that the attacker needed to be a member of the same organization as the victim in order to obtain the victim's correct ID, which was required to carry out the attack.
📂 Report JSON File: 3367292
@hackeronereports
🎯 New Report #3255910: Vulnerability: XML-RPC Interface Enabled and Accessible
🔺Severity: null
👽 Reporter: emad2466
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-10-10 18:24:26
📝 Summary: null
📂 Report JSON File: 3255910
@hackeronereports
🔺Severity: null
👽 Reporter: emad2466
⭐️ Reputation: 100
🛠 State: informative
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-10-10 18:24:26
📝 Summary: null
📂 Report JSON File: 3255910
@hackeronereports
🎯 New Report #3253725: SameSite restrictions are lifted, and SameSite:Strict cookie are being sent.
🔺Severity: High
👽 Reporter: mingijung
⭐️ Reputation: 250
🛠 State: resolved
💼 Team: Brave Software
💵 Bounty: 500
🕐 Submitted: 2025-07-15
⏰ Disclosed: 2025-10-15 05:41:30
📝 Summary: A vulnerability was discovered where SameSite=Strict cookies were being sent during cross-site navigations, even though they should have been restricted under the SameSite policy. This was caused by the absence of the Sec-Fetch-Site: cross-site header, which is normally used to prevent such bypasses and protect against CSRF attacks. The issue was reported to have been observed in Brave browser version 1.80.120 during a window operation.
📂 Report JSON File: 3253725
@hackeronereports
🔺Severity: High
👽 Reporter: mingijung
⭐️ Reputation: 250
🛠 State: resolved
💼 Team: Brave Software
💵 Bounty: 500
🕐 Submitted: 2025-07-15
⏰ Disclosed: 2025-10-15 05:41:30
📝 Summary: A vulnerability was discovered where SameSite=Strict cookies were being sent during cross-site navigations, even though they should have been restricted under the SameSite policy. This was caused by the absence of the Sec-Fetch-Site: cross-site header, which is normally used to prevent such bypasses and protect against CSRF attacks. The issue was reported to have been observed in Brave browser version 1.80.120 during a window operation.
📂 Report JSON File: 3253725
@hackeronereports
🎯 New Report #3313408: OneAgent Unprivileged NTLM User Coercion
🔺Severity: Medium
👽 Reporter: remiec
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Dynatrace
💵 Bounty: 750
🕐 Submitted: 2025-08-25
⏰ Disclosed: 2025-10-15 08:01:47
📝 Summary: null
📂 Report JSON File: 3313408
@hackeronereports
🔺Severity: Medium
👽 Reporter: remiec
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Dynatrace
💵 Bounty: 750
🕐 Submitted: 2025-08-25
⏰ Disclosed: 2025-10-15 08:01:47
📝 Summary: null
📂 Report JSON File: 3313408
@hackeronereports
🎯 New Report #3249624: Path Traversal Vulnerability in Nextcloud Tables Enables Arbitrary File Exfiltration of Any Files Supported by PhpSpreadsheet Library
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 391
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 750
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-10-16 06:52:20
📝 Summary: A path traversal vulnerability was discovered in Nextcloud Tables. This vulnerability allowed the exfiltration of any files supported by the PhpSpreadsheet library.
📂 Report JSON File: 3249624
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 391
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 750
🕐 Submitted: 2025-07-13
⏰ Disclosed: 2025-10-16 06:52:20
📝 Summary: A path traversal vulnerability was discovered in Nextcloud Tables. This vulnerability allowed the exfiltration of any files supported by the PhpSpreadsheet library.
📂 Report JSON File: 3249624
@hackeronereports
🎯 New Report #3104356: Blu-ray Disc Java Sandbox Escape via two vulnerabilities
🔺Severity: Medium
👽 Reporter: theflow0
⭐️ Reputation: 657
🛠 State: resolved
💼 Team: PlayStation
💵 Bounty: 5000
🕐 Submitted: 2025-04-22
⏰ Disclosed: 2025-10-18 00:35:23
📝 Summary: Two vulnerabilities in Blu-ray Disc Java (bd-j) related to the Inter-Xlet Communication (Ixc) implementation were discovered. The first vulnerability allowed invoking methods in privileged context by registering a remote object that implements an interface extending java.rmi.Remote. The second vulnerability enabled privileged method invocation by setting a custom method in the stub class generated for remote object registration. Together, these vulnerabilities could be exploited to disable the Java sandbox.
📂 Report JSON File: 3104356
@hackeronereports
🔺Severity: Medium
👽 Reporter: theflow0
⭐️ Reputation: 657
🛠 State: resolved
💼 Team: PlayStation
💵 Bounty: 5000
🕐 Submitted: 2025-04-22
⏰ Disclosed: 2025-10-18 00:35:23
📝 Summary: Two vulnerabilities in Blu-ray Disc Java (bd-j) related to the Inter-Xlet Communication (Ixc) implementation were discovered. The first vulnerability allowed invoking methods in privileged context by registering a remote object that implements an interface extending java.rmi.Remote. The second vulnerability enabled privileged method invocation by setting a custom method in the stub class generated for remote object registration. Together, these vulnerabilities could be exploited to disable the Java sandbox.
📂 Report JSON File: 3104356
@hackeronereports
🎯 New Report #3058919: Application Level DoS - Large Markdown Payload in Reply Section Leading to Resource Exhaustion
🔺Severity: High
👽 Reporter: theteatoast
⭐️ Reputation: 356
🛠 State: resolved
💼 Team: Discourse
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-10-18 16:47:02
📝 Summary: A Denial of Service (DoS) vulnerability was identified in the reply section of the web application. Submitting an excessively large markup payload (approximately 800,000 characters) resulted in the server taking 30 seconds to respond before returning an HTTP/2 502 Bad Gateway error, indicating potential resource exhaustion or backend service failure.
📂 Report JSON File: 3058919
@hackeronereports
🔺Severity: High
👽 Reporter: theteatoast
⭐️ Reputation: 356
🛠 State: resolved
💼 Team: Discourse
💵 Bounty: null
🕐 Submitted: 2025-03-25
⏰ Disclosed: 2025-10-18 16:47:02
📝 Summary: A Denial of Service (DoS) vulnerability was identified in the reply section of the web application. Submitting an excessively large markup payload (approximately 800,000 characters) resulted in the server taking 30 seconds to respond before returning an HTTP/2 502 Bad Gateway error, indicating potential resource exhaustion or backend service failure.
📂 Report JSON File: 3058919
@hackeronereports
🎯 New Report #3383095: DNS Rebinding Attack
🔺Severity: Critical
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: informative
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:33:19
📝 Summary: null
📂 Report JSON File: 3383095
@hackeronereports
🔺Severity: Critical
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: informative
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:33:19
📝 Summary: null
📂 Report JSON File: 3383095
@hackeronereports
🎯 New Report #3384150: Arbitrary File Write
🔺Severity: High
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:19:02
📝 Summary: A path traversal vulnerability was discovered in the protodump tool. The vulnerability allowed for arbitrary file writes outside the intended output directory due to insufficient validation of the go package option extracted from embedded protobuf descriptors. The Filename() function extracted the go package option without sanitization, enabling an attacker to create a malicious binary with a crafted go package value containing path traversal sequences. When the user ran protodump on this binary, the tool wrote the extracted proto file to an arbitrary location on the filesystem.
📂 Report JSON File: 3384150
@hackeronereports
🔺Severity: High
👽 Reporter: newby99
⭐️ Reputation: 178
🛠 State: resolved
💼 Team: arkadiyt-projects
💵 Bounty: null
🕐 Submitted: 2025-10-14
⏰ Disclosed: 2025-10-19 21:19:02
📝 Summary: A path traversal vulnerability was discovered in the protodump tool. The vulnerability allowed for arbitrary file writes outside the intended output directory due to insufficient validation of the go package option extracted from embedded protobuf descriptors. The Filename() function extracted the go package option without sanitization, enabling an attacker to create a malicious binary with a crafted go package value containing path traversal sequences. When the user ran protodump on this binary, the tool wrote the extracted proto file to an arbitrary location on the filesystem.
📂 Report JSON File: 3384150
@hackeronereports
🎯 New Report #3329361: 2FA bypass possible on https://authsvc.singlestore.com
🔺Severity: Medium
👽 Reporter: axolot23
⭐️ Reputation: 113
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-09-06
⏰ Disclosed: 2025-10-22 06:44:27
📝 Summary: A vulnerability was discovered that allowed the 2FA authentication mechanism to be bypassed completely. An attacker could access the victim's account by only knowing the email address and password, without requiring the 2FA code.
📂 Report JSON File: 3329361
@hackeronereports
🔺Severity: Medium
👽 Reporter: axolot23
⭐️ Reputation: 113
🛠 State: resolved
💼 Team: SingleStore
💵 Bounty: null
🕐 Submitted: 2025-09-06
⏰ Disclosed: 2025-10-22 06:44:27
📝 Summary: A vulnerability was discovered that allowed the 2FA authentication mechanism to be bypassed completely. An attacker could access the victim's account by only knowing the email address and password, without requiring the 2FA code.
📂 Report JSON File: 3329361
@hackeronereports
🎯 New Report #3091390: Reflected Cross-Site Scripting (XSS) in Revive Adserver 5.5.2
🔺Severity: Medium
👽 Reporter: env bak
⭐️ Reputation: 104
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-04-14
⏰ Disclosed: 2025-10-22 09:54:05
📝 Summary: null
📂 Report JSON File: 3091390
@hackeronereports
🔺Severity: Medium
👽 Reporter: env bak
⭐️ Reputation: 104
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-04-14
⏰ Disclosed: 2025-10-22 09:54:05
📝 Summary: null
📂 Report JSON File: 3091390
@hackeronereports
🎯 New Report #3393539: Memory leak in Curl auth create ntlm type3 message
🔺Severity: Low
👽 Reporter: tjbecker theori
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-21
⏰ Disclosed: 2025-10-28 14:48:40
📝 Summary: null
📂 Report JSON File: 3393539
@hackeronereports
🔺Severity: Low
👽 Reporter: tjbecker theori
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-21
⏰ Disclosed: 2025-10-28 14:48:40
📝 Summary: null
📂 Report JSON File: 3393539
@hackeronereports
🎯 New Report #268221: No Confirmation Email For Email Change
🔺Severity: Low
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:38:56
📝 Summary: null
📂 Report JSON File: 268221
@hackeronereports
🔺Severity: Low
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:38:56
📝 Summary: null
📂 Report JSON File: 268221
@hackeronereports
🎯 New Report #268224: Information Disclosure
🔺Severity: Medium
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:34:26
📝 Summary: null
📂 Report JSON File: 268224
@hackeronereports
🔺Severity: Medium
👽 Reporter: craxermgr
⭐️ Reputation: 105
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-09-14
⏰ Disclosed: 2025-10-31 17:34:26
📝 Summary: null
📂 Report JSON File: 268224
@hackeronereports
🎯 New Report #300164: REDIRECTION VULNERABILITY/HOST HEADER INJECTION VULNERABILITY
🔺Severity: Medium
👽 Reporter: vyshnav nk
⭐️ Reputation: 50
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-12-23
⏰ Disclosed: 2025-10-31 17:33:52
📝 Summary: null
📂 Report JSON File: 300164
@hackeronereports
🔺Severity: Medium
👽 Reporter: vyshnav nk
⭐️ Reputation: 50
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2017-12-23
⏰ Disclosed: 2025-10-31 17:33:52
📝 Summary: null
📂 Report JSON File: 300164
@hackeronereports
🎯 New Report #304073: Missing restriction on string size of Full Name at browser.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-01-11
⏰ Disclosed: 2025-10-31 17:33:31
📝 Summary: null
📂 Report JSON File: 304073
@hackeronereports
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-01-11
⏰ Disclosed: 2025-10-31 17:33:31
📝 Summary: null
📂 Report JSON File: 304073
@hackeronereports
🎯 New Report #377565: Can view all username leaked in https://core.blockstack.org
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🔺Severity: null
👽 Reporter: myskar
⭐️ Reputation: 1094
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2018-07-05
⏰ Disclosed: 2025-10-31 17:32:59
📝 Summary: null
📂 Report JSON File: 377565
@hackeronereports
🎯 New Report #716647: Invalidate active sessions after password change
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🔺Severity: Low
👽 Reporter: droop3r
⭐️ Reputation: 251
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-10-17
⏰ Disclosed: 2025-10-31 17:32:49
📝 Summary: null
📂 Report JSON File: 716647
@hackeronereports
🎯 New Report #910732: blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🔺Severity: None
👽 Reporter: 0x1 aulia
⭐️ Reputation: 93
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2020-06-29
⏰ Disclosed: 2025-10-31 17:32:21
📝 Summary: null
📂 Report JSON File: 910732
@hackeronereports
🎯 New Report #541760: Blockstack Browser For Mac leaks "Core API Password" to 3rd parties
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports
🔺Severity: Low
👽 Reporter: frozensolid
⭐️ Reputation: 673
🛠 State: informative
💼 Team: Hiro
💵 Bounty: null
🕐 Submitted: 2019-04-18
⏰ Disclosed: 2025-10-31 17:32:08
📝 Summary: null
📂 Report JSON File: 541760
@hackeronereports