Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4323Detecting and exploiting mass-assignments in order to manipulate user columns and read private messages Mass assignment NA Paul (@padannewitz) Bug Bounty2019-02-052023-06-13
2831How I Gain Access to the Server Administration of a Million-Dollar Company Privilege escalation Mass assignment NA Marx Chryz Del Mundo Bug Bounty2021-02-082023-06-13
2557Mass Assignment exploitation in the wild - Escalating privileges in style Mass assignment Privilege escalation NA Gal Nagli (@naglinagli) Bug Bounty2021-05-142023-06-13
2486Story of Account Takeover : Using Social Login with Mass Assignment Vulnerability to hack accounts ! Mass assignment Account takeover NA Mohammad Kaif Bug Bounty2021-06-132023-06-13
2465Accessing Restricted Documents With Extra JSON Body Content Mass assignment Authorization flaw NA Imran Huda (@imranHudaA) Bug Bounty2021-06-182023-06-13
2324Simple HTML Injection to $250 Account takeover Mass assignment NA Ahmad Halabi (@Ahmad_Halabi_) Bug Bounty2021-08-142023-06-13
1953One Click To Account Takeover Mass assignment NA M7.Arman (@ArmanSecurity) Bug Bounty2022-01-012023-06-13
1596[EN] Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS Stored XSS Mass assignment Security code review pass Culture Aethlios (@AethliosIK) Bug Bounty2022-04-262023-06-13
1445Hacking into the worldwide Jacuzzi SmartTub network SPA Android JWT Privilege escalation Mass assignment Jacuzzi Group SmartTub Eaton Z. (@XeEaton) Bug Bounty2022-06-202023-06-13
1414[BugBounty] how do I get a premium tier account without paying a penny Mass assignment Payment bypass NA Marzuki (@aizack_ma) Bug Bounty2022-06-292023-06-13
1310Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app Mass assignment freeCodeCamp Laurence Tennant Bug Bounty2022-07-262023-06-13
1182Break the Logic: Insecure Parameters (€300) Parameter manipulation Logic flaw Mass assignment NA can1337 (@canmustdie) Bug Bounty2022-08-242023-06-13
1055Mass Assignment Leading to Pre Account Takeover Mass assignment NA Cyberali Bug Bounty2022-09-212023-06-13
715Privilege Escalation to remove the owner from the organization Privilege escalation Mass assignment NA Hemant Kumar Bug Bounty2022-12-092023-06-13
621Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Account takeover SSO RCE Authorization bypass SQL injection Mass assignment Information disclosure Kia Honda Infiniti Nissan Acura Mercedes-Benz Hyundai Genesis BMW Rolls Royce Ferrari Spireon Ford Reviver Porsche Toyota Jaguar Land Rover SiriusXM Sam Curry (@samwcyo) Bug Bounty2023-01-032023-06-13
284Easy $$$ via API params manipulation leading to bypassing the email verification block Mass assignment Email verification bypass NA Fares Walid (@SirBagoza) Bug Bounty2023-03-182023-06-13
119Mass Assignment leads to the victim’s account being inaccessible forever Mass assignment Logic flaw NA Arman (@M7arm4n) Bug Bounty2023-05-052023-06-13
61From Response To Request, Adding Your Own Variables Inside Of GraphQL Queries For Account Take Over GraphQL IDOR Mass assignment NA Tom Neaves Bug Bounty2023-05-232023-06-13