Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4968Device Authorization Bypass! Authorization flaw NA Hassan Khan Yusufzai Bug Bounty2017-09-252023-06-13
4201Google Groups Authorization Bypass Authorization flaw Google Daniel Marad Bug Bounty2019-04-152023-06-13
3850Bypassing GitHub%27s OAuth flow OAuth Authorization bypass GitHub Teddy Katz (@not_aardvark) Bug Bounty2019-11-052023-06-13
3639Account Hijack using Authorization bypass $$$$ Account takeover Authorization flaw NA Bhavesh Thakur (@Bhavesh_Thakur_) Bug Bounty2020-02-282023-06-13
3271Authorization bypass in Google’s ticketing system (Google-GUTS) Authorization flaw Google Zohar Shachar Bug Bounty2020-07-282023-06-13
3109We Hacked Apple for 3 Months: Here’s What We Found RCE Authentication bypass Authorization bypass SSRF XXE Blind XSS IDOR OS command injection SQL injection Apple Sam Curry (@samwcyo) Bug Bounty2020-10-072023-06-13
3106Exploiting Admin Panel Like a Boss Authorization bypass Weak credentials NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-082023-06-13
3056From a 500 error to Django admin takeover Authorization bypass Account takeover NA Shashank (@cyberboyIndia) Bug Bounty2020-11-032023-06-13
2694Multiple Authorization bypass issues in Google%27s Richmedia Studio Authorization flaw Google Zohar Shachar Bug Bounty2021-03-242023-06-13
1938Authorization bypass — Gmail Spoofing Google 7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) Bug Bounty2022-01-062023-06-13
621Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Account takeover SSO RCE Authorization bypass SQL injection Mass assignment Information disclosure Kia Honda Infiniti Nissan Acura Mercedes-Benz Hyundai Genesis BMW Rolls Royce Ferrari Spireon Ford Reviver Porsche Toyota Jaguar Land Rover SiriusXM Sam Curry (@samwcyo) Bug Bounty2023-01-032023-06-13
357GitHub Security Lab audited DataHub: Here’s what they found SSRF Insecure deserialization Cypher injection Authentication bypass Authorization bypass XSS Open redirect JWT JSON injection Cryptographic issues Session expiration issue Security code review DataHub Alvaro Muñoz (@pwntester) Bug Bounty2023-03-032023-06-13
324Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover Authorization bypass JWT Account takeover Microsoft (ClipChamp) Vikas Anil Sharma (@vikzsharma) Bug Bounty2023-03-102023-06-13
274Improper Privilege Management in Grails Spring Security Core <= 5.1.0 (CVE-2022-41923) Privilege escalation Authorization bypass Grails Benjamin Sepe (@Butanal_C4H8O) Bug Bounty2023-03-212023-06-13
231Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server RCE SSTI Authorization bypass Groovy scripting Hitachi Vantara (Pentaho) Harry Withington Bug Bounty2023-04-042023-06-13
171GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts Cloud OAuth Authorization bypass Google (GCP) Astrix Security (@AstrixSecurity) Bug Bounty2023-04-202023-06-13
104Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3 RCE Authorization bypass Security code review Sitecore Dylan Pindur Bug Bounty2023-05-102023-06-13