Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4397Client side validation strikes again: PIN code bypass ! Client-side enforcement of server-side security Authentication bypass Authorization flaw Netflix Linxo Davy (@RandoriSec) Bug Bounty2018-12-222023-06-13
4095Using Burp Suite match and replace settings to escalate your user privileges and find hidden features Client-side enforcement of server-side security New Relic Jon Bottarini (@jon_bottarini) Bug Bounty2019-06-172023-06-13
3676How Inspect Element Got me a Bounty Client-side enforcement of server-side security NA Aditya Soni (@hetroublemakr) Bug Bounty2020-02-062023-06-13
3355Using Inspect Element to Bypass Security restrictions | Bug Bounty POC Client-side enforcement of server-side security NA Muhammad Khizer Javed (@khizer_javed47) Bug Bounty2020-06-302023-06-13
3285Hunting Android Application Bugs Using Android Studio. Authorization flaw Client-side enforcement of server-side security Information disclosure NA Tarek Mohammed (@Conan0x3) Bug Bounty2020-07-242023-06-13
3183Unhiding the hidden Client-side enforcement of server-side security Authorization flaw CSRF NA I am Broot Bug Bounty2020-08-312023-06-13
2621DMCA.COM Hack, Full Disclosure (With Proof-of-Concept) Privilege escalation Client-side enforcement of server-side security Stored XSS Broken Access Control DMCA Joël Aviad Ossi Bug Bounty2021-04-212023-06-13
2349How the use of hidden form fields lead to Email verification bypass Email verification bypass Client-side enforcement of server-side security NA Yash Swarup (@wazirsec) Bug Bounty2021-08-032023-06-13
2273Broken Access Control Leads To Change Of Admin Details Privilege escalation Client-side enforcement of server-side security NA V3D (@v3d_bug) Bug Bounty2021-08-312023-06-13
2019Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials. Client-side enforcement of server-side security Privilege escalation U.S. General Services Administration Hazem Brini (@ImJungsuu) Bug Bounty2021-12-072023-06-13
1448Account Takeover by OTP bypass Information disclosure Client-side enforcement of server-side security OTP bypass Account takeover NA Vaibhav Kumar Srivastava Bug Bounty2022-06-192023-06-13
1173Break the Logic: 5 Different Perspectives in Single Page (€1500) Client-side enforcement of server-side security IDOR Authorization flaw NA can1337 (@canmustdie) Bug Bounty2022-08-262023-06-13
1013Security vs Compliance-Cloudflare Password Policy Restriction Bypass Client-side enforcement of server-side security Cloudflare Lohith Gowda M (@lohigowda_in) Bug Bounty2022-09-292023-06-13
553How i Hacked Scopely with “Sign in with Google” Account takeover CORS misconfiguration Client-side enforcement of server-side security OAuth Scopely Ph.Hitachi Bug Bounty2023-01-232023-06-13