🎯 New Report #3426761: HTML Injection in Emails on login.mtb.com via givenName parameter leads to phishing attacks
🔺Severity: Medium
👽 Reporter: ozgun32
⭐️ Reputation: 207
🛠 State: resolved
💼 Team: M T Bank Vulnerability Disclosure
💵 Bounty: null
🕐 Submitted: 2025-11-15
⏰ Disclosed: 2025-11-24 14:07:16
📝 Summary: A vulnerability was found that allowed HTML injection in emails on login.mtb.com via the givenName parameter. This vulnerability could have enabled phishing attacks.
📂 Report JSON File: 3426761
@hackeronereports
🔺Severity: Medium
👽 Reporter: ozgun32
⭐️ Reputation: 207
🛠 State: resolved
💼 Team: M T Bank Vulnerability Disclosure
💵 Bounty: null
🕐 Submitted: 2025-11-15
⏰ Disclosed: 2025-11-24 14:07:16
📝 Summary: A vulnerability was found that allowed HTML injection in emails on login.mtb.com via the givenName parameter. This vulnerability could have enabled phishing attacks.
📂 Report JSON File: 3426761
@hackeronereports
😁2
🎯 New Report #3432833: [SFTP TOCTOU Race Condition in Upload Resume Logic Leads to Arbitrary File Append](https://hackerone.com/reports/3432833)
🔺Severity: Medium
👽 Reporter: cainvsilf
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-19
⏰ Disclosed: 2025-11-24 18:55:10
📝 Summary: null
📂 Report JSON File: 3432833
@hackeronereports
🔺Severity: Medium
👽 Reporter: cainvsilf
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-11-19
⏰ Disclosed: 2025-11-24 18:55:10
📝 Summary: null
📂 Report JSON File: 3432833
@hackeronereports
🎯 New Report #1916400: High resource consumption by insufficient sanitization of forum threads pagination
🔺Severity: Medium
👽 Reporter: maskopatol
⭐️ Reputation: 3795
🛠 State: resolved
💼 Team: Flickr
💵 Bounty: 479
🕐 Submitted: 2023-03-24
⏰ Disclosed: 2025-11-24 22:33:46
📝 Summary: The forum threads pagination functionality was insufficiently sanitized, leading to high resource consumption. When a page number was provided in the URL that exceeded the number of available pages, an infinite loop was triggered, generating excessive markup on each iteration. The issue was resolved by correcting the logic to avoid generating links to non-existent pages.
📂 Report JSON File: 1916400
@hackeronereports
🔺Severity: Medium
👽 Reporter: maskopatol
⭐️ Reputation: 3795
🛠 State: resolved
💼 Team: Flickr
💵 Bounty: 479
🕐 Submitted: 2023-03-24
⏰ Disclosed: 2025-11-24 22:33:46
📝 Summary: The forum threads pagination functionality was insufficiently sanitized, leading to high resource consumption. When a page number was provided in the URL that exceeded the number of available pages, an infinite loop was triggered, generating excessive markup on each iteration. The issue was resolved by correcting the logic to avoid generating links to non-existent pages.
📂 Report JSON File: 1916400
@hackeronereports
🎯 New Report #3434156: Username Validation Bypass
🔺Severity: Medium
👽 Reporter: kassem s94
⭐️ Reputation: 10331
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-11-19
⏰ Disclosed: 2025-11-26 14:18:23
📝 Summary: null
📂 Report JSON File: 3434156
@hackeronereports
🔺Severity: Medium
👽 Reporter: kassem s94
⭐️ Reputation: 10331
🛠 State: resolved
💼 Team: Revive Adserver
💵 Bounty: null
🕐 Submitted: 2025-11-19
⏰ Disclosed: 2025-11-26 14:18:23
📝 Summary: null
📂 Report JSON File: 3434156
@hackeronereports
🎯 New Report #2932960: [my.stripo.email Blind SSRF Vulnerability in Stripo App Export via Missing Endpoints Export Email Message to Zapier](https://hackerone.com/reports/2932960)
🔺Severity: Critical
👽 Reporter: odaysec
⭐️ Reputation: null
🛠 State: resolved
💼 Team: Stripo Inc
💵 Bounty: null
🕐 Submitted: 2025-01-13
⏰ Disclosed: 2025-12-01 08:22:34
📝 Summary: A critical Blind SSRF (Server-Side Request Forgery) vulnerability was identified in the export service of the Stripo app. The vulnerability existed in the endpoint
📂 Report JSON File: 2932960
@hackeronereports
🔺Severity: Critical
👽 Reporter: odaysec
⭐️ Reputation: null
🛠 State: resolved
💼 Team: Stripo Inc
💵 Bounty: null
🕐 Submitted: 2025-01-13
⏰ Disclosed: 2025-12-01 08:22:34
📝 Summary: A critical Blind SSRF (Server-Side Request Forgery) vulnerability was identified in the export service of the Stripo app. The vulnerability existed in the endpoint
/exportservice/v3/exports/WEBHOOK/accounts, where malicious input could be provided in the webhookUrl parameter, triggering SSRF and allowing the server to make unauthorized HTTP requests to attacker-controlled systems.📂 Report JSON File: 2932960
@hackeronereports
🎯 New Report #3417967: Potential SQL Injection when annotating FilteredRelation on PostgreSQL
🔺Severity: High
👽 Reporter: stackered
⭐️ Reputation: 212
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-12-02 15:28:06
📝 Summary: A potential SQL injection vulnerability was discovered in Django's annotation of FilteredRelation on PostgreSQL. The vulnerability was caused by an incomplete regular expression filter in the FORBIDDEN ALIAS PATTERN. This allowed user input to be interpreted as raw strings, potentially enabling the execution of malicious SQL queries. The vulnerability was reported to the Django security team.
📂 Report JSON File: 3417967
@hackeronereports
🔺Severity: High
👽 Reporter: stackered
⭐️ Reputation: 212
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-11-09
⏰ Disclosed: 2025-12-02 15:28:06
📝 Summary: A potential SQL injection vulnerability was discovered in Django's annotation of FilteredRelation on PostgreSQL. The vulnerability was caused by an incomplete regular expression filter in the FORBIDDEN ALIAS PATTERN. This allowed user input to be interpreted as raw strings, potentially enabling the execution of malicious SQL queries. The vulnerability was reported to the Django security team.
📂 Report JSON File: 3417967
@hackeronereports
🎯 New Report #2890071: admin audit does not log actions on files in a group folder
🔺Severity: Medium
👽 Reporter: klipz
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-12-09
⏰ Disclosed: 2025-12-05 08:22:06
📝 Summary: The admin audit app in Nextcloud versions prior to 24.0.4 did not log actions on files in a group folder.
📂 Report JSON File: 2890071
@hackeronereports
🔺Severity: Medium
👽 Reporter: klipz
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-12-09
⏰ Disclosed: 2025-12-05 08:22:06
📝 Summary: The admin audit app in Nextcloud versions prior to 24.0.4 did not log actions on files in a group folder.
📂 Report JSON File: 2890071
@hackeronereports
🎯 New Report #3247499: Deck app allowed user with "Can share" permission to modify permissions of other non-owners
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-07-11
⏰ Disclosed: 2025-12-05 08:20:21
📝 Summary: The Deck app in Nextcloud allowed users with "Can share" permission to modify the permissions of other non-owners.
📂 Report JSON File: 3247499
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-07-11
⏰ Disclosed: 2025-12-05 08:20:21
📝 Summary: The Deck app in Nextcloud allowed users with "Can share" permission to modify the permissions of other non-owners.
📂 Report JSON File: 3247499
@hackeronereports
🎯 New Report #3275810: Calendar app allowed booking appointments without the generated token
🔺Severity: Low
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-07-29
⏰ Disclosed: 2025-12-05 08:18:39
📝 Summary: The calendar app was found to allow booking appointments without the necessary generated token, which could have led to unauthorized access.
📂 Report JSON File: 3275810
@hackeronereports
🔺Severity: Low
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-07-29
⏰ Disclosed: 2025-12-05 08:18:39
📝 Summary: The calendar app was found to allow booking appointments without the necessary generated token, which could have led to unauthorized access.
📂 Report JSON File: 3275810
@hackeronereports
🎯 New Report #3112033: Calendar attachments of local files are offered to downloaded
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 100
🕐 Submitted: 2025-04-25
⏰ Disclosed: 2025-12-05 08:18:13
📝 Summary: A security vulnerability in calendar attachments of local files was discovered, where users were offered to download the attachments.
📂 Report JSON File: 3112033
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 100
🕐 Submitted: 2025-04-25
⏰ Disclosed: 2025-12-05 08:18:13
📝 Summary: A security vulnerability in calendar attachments of local files was discovered, where users were offered to download the attachments.
📂 Report JSON File: 3112033
@hackeronereports
🎯 New Report #3137895: Missing ownership check in Tables app allows moving columns into tables of other users
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-05-10
⏰ Disclosed: 2025-12-05 08:17:45
📝 Summary: The Tables app in the specified software had a vulnerability that allowed moving columns into tables of other users without proper ownership checks.
📂 Report JSON File: 3137895
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-05-10
⏰ Disclosed: 2025-12-05 08:17:45
📝 Summary: The Tables app in the specified software had a vulnerability that allowed moving columns into tables of other users without proper ownership checks.
📂 Report JSON File: 3137895
@hackeronereports
🎯 New Report #3138721: Tables app allowed users to view columns metadata information of any table
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-05-11
⏰ Disclosed: 2025-12-05 08:17:22
📝 Summary: The Tables app allowed users to view columns metadata information of any table.
📂 Report JSON File: 3138721
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 250
🕐 Submitted: 2025-05-11
⏰ Disclosed: 2025-12-05 08:17:22
📝 Summary: The Tables app allowed users to view columns metadata information of any table.
📂 Report JSON File: 3138721
@hackeronereports
🎯 New Report #3247386: Participants were able to blindly delete poll drafts of other users by ID
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-07-11
⏰ Disclosed: 2025-12-05 08:16:59
📝 Summary: Participants were able to blindly delete poll drafts of other users by ID.
📂 Report JSON File: 3247386
@hackeronereports
🔺Severity: Medium
👽 Reporter: daroo
⭐️ Reputation: 460
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-07-11
⏰ Disclosed: 2025-12-05 08:16:59
📝 Summary: Participants were able to blindly delete poll drafts of other users by ID.
📂 Report JSON File: 3247386
@hackeronereports
🎯 New Report #3338748: Approval app allows users to request approval for other users file
🔺Severity: Medium
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-15
⏰ Disclosed: 2025-12-05 08:11:01
📝 Summary: A security vulnerability was discovered in the Approval app that allowed users to request approval for other users' files. The vulnerability was addressed in a security advisory.
📂 Report JSON File: 3338748
@hackeronereports
🔺Severity: Medium
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-15
⏰ Disclosed: 2025-12-05 08:11:01
📝 Summary: A security vulnerability was discovered in the Approval app that allowed users to request approval for other users' files. The vulnerability was addressed in a security advisory.
📂 Report JSON File: 3338748
@hackeronereports
🎯 New Report #3334165: Nextcloud Tables v1 Share Enumeration Without Authorization (Regression of CVE-2024-52507)
🔺Severity: Low
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-11
⏰ Disclosed: 2025-12-05 08:10:11
📝 Summary: A vulnerability was discovered in Nextcloud Tables v1 that allowed unauthorized users to enumerate shares. The vulnerability was a regression of a previously addressed issue, CVE-2024-52507.
📂 Report JSON File: 3334165
@hackeronereports
🔺Severity: Low
👽 Reporter: 0x0doteth
⭐️ Reputation: 524
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2025-09-11
⏰ Disclosed: 2025-12-05 08:10:11
📝 Summary: A vulnerability was discovered in Nextcloud Tables v1 that allowed unauthorized users to enumerate shares. The vulnerability was a regression of a previously addressed issue, CVE-2024-52507.
📂 Report JSON File: 3334165
@hackeronereports
🎯 New Report #3357808: Stored XSS Vulnerability via SVG File
🔺Severity: Medium
👽 Reporter: aptroom
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-09-25
⏰ Disclosed: 2025-12-05 10:33:23
📝 Summary: A stored XSS vulnerability was discovered in Nextcloud related to the handling of SVG files. The vulnerability allowed the execution of arbitrary JavaScript code.
📂 Report JSON File: 3357808
@hackeronereports
🔺Severity: Medium
👽 Reporter: aptroom
⭐️ Reputation: 122
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: 150
🕐 Submitted: 2025-09-25
⏰ Disclosed: 2025-12-05 10:33:23
📝 Summary: A stored XSS vulnerability was discovered in Nextcloud related to the handling of SVG files. The vulnerability allowed the execution of arbitrary JavaScript code.
📂 Report JSON File: 3357808
@hackeronereports
🎯 New Report #3452015: Unauthenticated GraphQL access by prepending schema to private operations
🔺Severity: Medium
👽 Reporter: pwnie
⭐️ Reputation: 1844
🛠 State: resolved
💼 Team: Enjin
💵 Bounty: null
🕐 Submitted: 2025-12-04
⏰ Disclosed: 2025-12-05 15:10:45
📝 Summary: A security vulnerability was identified in the GraphQL schema of the Enjin Platform. The vulnerability allowed unauthorized access to the GraphQL schema by prepending " schema" to private operations. The vulnerability was discovered and reported by a security researcher. The specific location of the vulnerability within the platform-core repository was identified, and a fix was subsequently implemented to address the issue.
📂 Report JSON File: 3452015
@hackeronereports
🔺Severity: Medium
👽 Reporter: pwnie
⭐️ Reputation: 1844
🛠 State: resolved
💼 Team: Enjin
💵 Bounty: null
🕐 Submitted: 2025-12-04
⏰ Disclosed: 2025-12-05 15:10:45
📝 Summary: A security vulnerability was identified in the GraphQL schema of the Enjin Platform. The vulnerability allowed unauthorized access to the GraphQL schema by prepending " schema" to private operations. The vulnerability was discovered and reported by a security researcher. The specific location of the vulnerability within the platform-core repository was identified, and a fix was subsequently implemented to address the issue.
📂 Report JSON File: 3452015
@hackeronereports
🎯 New Report #3407352: curl built with GnuTLS backend defaults to weak crypto parameters
🔺Severity: None
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-31
⏰ Disclosed: 2025-12-08 10:45:24
📝 Summary: null
📂 Report JSON File: 3407352
@hackeronereports
🔺Severity: None
👽 Reporter: nyymi
⭐️ Reputation: 1257
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-10-31
⏰ Disclosed: 2025-12-08 10:45:24
📝 Summary: null
📂 Report JSON File: 3407352
@hackeronereports
🎯 New Report #3455037: Certificate Hostname Validation Bypass via Leading Dot in Hostname
🔺Severity: Medium
👽 Reporter: 4bccc
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-06
⏰ Disclosed: 2025-12-09 23:29:46
📝 Summary: null
📂 Report JSON File: 3455037
@hackeronereports
🔺Severity: Medium
👽 Reporter: 4bccc
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-12-06
⏰ Disclosed: 2025-12-09 23:29:46
📝 Summary: null
📂 Report JSON File: 3455037
@hackeronereports
🎯 New Report #3316910: Second-Order XSS via javascript protocol in MCP Server Portal Apps leads to ATO
🔺Severity: Low
👽 Reporter: matured kazama
⭐️ Reputation: 2312
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-08-27
⏰ Disclosed: 2025-12-16 09:47:20
📝 Summary: The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect uri containing JavaScript code, obtain a client id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.
📂 Report JSON File: 3316910
@hackeronereports
🔺Severity: Low
👽 Reporter: matured kazama
⭐️ Reputation: 2312
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-08-27
⏰ Disclosed: 2025-12-16 09:47:20
📝 Summary: The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect uri containing JavaScript code, obtain a client id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.
📂 Report JSON File: 3316910
@hackeronereports
🎯 New Report #3458235: [RCE Remote Code Execution via React Server Components Vulnerability CVE-2025-55182](https://hackerone.com/reports/3458235)
🔺Severity: Critical
👽 Reporter: kanon4
⭐️ Reputation: 965
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-09
⏰ Disclosed: 2025-12-18 16:17:43
📝 Summary: null
📂 Report JSON File: 3458235
@hackeronereports
🔺Severity: Critical
👽 Reporter: kanon4
⭐️ Reputation: 965
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2025-12-09
⏰ Disclosed: 2025-12-18 16:17:43
📝 Summary: null
📂 Report JSON File: 3458235
@hackeronereports