Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5059Godaddy XSS affects parked domains redirector/processor! Reflected XSS GoDaddy Mohamed A. Baset Bug Bounty2017-06-112023-06-13
5050Road to (unauthenticated) recovery: downloading GitHub SSO bypass codes Authorization flaw GitHub Yasin Soliman (@SecurityYasin) Bug Bounty2017-06-252023-06-13
3495DOM-Based XSS at accounts.google.com by Google Voice Extension. DOM XSS Google missoum1307 (@missoum1307) Bug Bounty2020-05-072023-06-13
3129Taking down the SSO, Account Takeover in the Websites of Kolesa due to Insecure JSONP Call Account takeover NA Yashar Shahinzadeh (@YShahinzadeh) Bug Bounty2020-09-282023-06-13
3111Research: The mass CSRFing of *.google.com/* products. CSRF Google Missoum Said (@missoum1307) Bug Bounty2020-10-072023-06-13
2768Stealing user passwords through a VPN’s SSO Open redirect SSTI NA Alain Mowat (@plopz0r) Bug Bounty2021-02-252023-06-13
2618New Clubhouse Security Vulnerabilities Could Happen to Any Growing Unicorn Logic flaw Clubhouse Katie Moussouris (@k8em0) Bug Bounty2021-04-212023-06-13
1949The Story Of How I Bypass SSO Login Authentication bypass NA zer0d Bug Bounty2022-01-022023-06-13
1915XXE in SAML SSO Writeup - Bug Bounty XXE NA Aditya Singh / rook1337 (@imrook1337) Bug Bounty2022-01-162023-06-13
1894How I was able to take over accounts in websites deal with Github as an SSO provider Bruteforce Lack of rate limiting SSO Email verification bypass Account takeover NA Khaled Mohamed Bug Bounty2022-01-252023-06-13
1696Bug Bounty Adventures: A NodeBB 0-day CSRF Account takeover SSO Authentication flaw Opera Marouane Mouhtadi (@Mar0_0uane) Bug Bounty2022-03-252023-06-13
1632Bypass Apple Corp SSO on Apple Admin Panel Path traversal Apple Stealthy (@stealthybugs) Bug Bounty2022-04-122023-06-13
1626Blinding Snort: Breaking The Modbus OT Preprocessor Memory corruption Cisco Claroty%27s Team82 (@Claroty) Bug Bounty2022-04-142023-06-13
1085Colorful Vulnerabilities Memory corruption Buffer Overflow OpenRazer Tal Lossos (@TalLossos) Bug Bounty2022-09-142023-06-13
1023Exploits Explained: 5 Unusual Authentication Bypass Techniques Authentication bypass JWT CMS SSO NA Ozgur Alp (@ozgur_bbh) Bug Bounty2022-09-282023-06-13
954Google SSO misconfiguration leading to Account Takeover Authentication bypass Account takeover SSO NA 0x4KD (@0x4kd) Bug Bounty2022-10-142023-06-13
690Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes SSO IDOR Missing authentication HAwebsso.nl Jonathan Bouman (@JonathanBouman) Bug Bounty2022-12-142023-06-13
677Cengage LTI Session Management Leakage SSO Session management issue Cengage Tony Porterfield Bug Bounty2022-12-202023-06-13
661Multiple authenticated blind SQL Injections in Sage XRT Business Exchange application Blind SQL injection Sage Mickaël Benassouli (@mickaelweb) Bug Bounty2022-12-212023-06-13
621Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Account takeover SSO RCE Authorization bypass SQL injection Mass assignment Information disclosure Kia Honda Infiniti Nissan Acura Mercedes-Benz Hyundai Genesis BMW Rolls Royce Ferrari Spireon Ford Reviver Porsche Toyota Jaguar Land Rover SiriusXM Sam Curry (@samwcyo) Bug Bounty2023-01-032023-06-13
571Azure Active Directory Flaw Allowed SAML Persistence Azure AD SAML SSO Microsoft (Azure) Secureworks Counter Threat Unit (@Secureworks) Bug Bounty2023-01-182023-06-13
503Discovering 5 XSS Vulnerabilities In a Simple Way With Xssor.go Reflected XSS NA Fares Walid (@SirBagoza) Bug Bounty2023-02-022023-06-13
497SSO Gadgets: Escalate (Self-)XSS to ATO SSO OAuth Account takeover Self-XSS Login CSRF NA Lauritz Holtmann (@_lauritz_) Bug Bounty2023-02-042023-06-13
458Hacking our way into internal DBs with hardcoded authentication keys JWT SSO Authentication bypass Security misconfiguration NA Ophion Security (@OphionSecurity) Bug Bounty2023-02-132023-06-13
429Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover Account takeover SSO OTP Authentication bypass NA Aidil Arief Bug Bounty2023-02-202023-06-13