2373 | Chaining Open Redirect with XSS to Account Takeover |
Open redirect
XSS
Account takeover |
NA |
Radian ID |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2368 | Account takeover via stored xss |
Stored XSS |
NA |
vikram naidu (@ImVikram7msd) |
Bug Bounty | 2021-07-30 | 2023-06-13 |
2364 | How I escalate my Self-Stored XSS to Account Takeover with the help of IDOR |
Self-XSS
IDOR
Account takeover |
HackerEarth |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2346 | Account Takeover (User + Admin) Via Password Reset |
Account takeover
Password reset
Logic flaw |
NA |
Hemant Patidar (@HemantSolo) |
Bug Bounty | 2021-08-05 | 2023-06-13 |
2336 | Fuzzing + IDOR = Admin TakeOver |
IDOR
Account takeover |
NA |
Gonzalo Carrasco (@0xCGonzalo) |
Bug Bounty | 2021-08-09 | 2023-06-13 |
2324 | Simple HTML Injection to $250 |
Account takeover
Mass assignment |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2321 | Why u should use burp to test Path Traversal Vulnerability and also get RXSS |
Path traversal
XSS
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2315 | How to Hack Apple ID |
XSS
Account takeover |
Apple |
Zemnmez (@zemnmez) |
Bug Bounty | 2021-08-17 | 2023-06-13 |
2313 | Account Takeover via Access Token Leakage |
IDOR
Information disclosure
Account takeover |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2300 | [$5K] Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO) |
Account takeover
Password reset
Information disclosure |
NA |
Aditya Sharma (@Assass1nmarcos) |
Bug Bounty | 2021-08-24 | 2023-06-13 |
2299 | One Endpoint, Two Account Takeovers |
Account takeover |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2021-08-24 | 2023-06-13 |
2289 | ChaosDB: Critical Vulnerability in Microsoft Azure Cosmos DB |
Account takeover
Local Privilege Escalation |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2281 | ATO of WordPress Website “4 digits €€€€ Bounty in 5 Minute!” |
Exposed registration page
Account takeover |
NA |
Ritesh Gohil (@RiteshG37659480) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2277 | Two account takeover bugs worth $4300 🎁 |
Account takeover
Privilege escalation
403 bypass
IDOR |
NA |
Usama Varikkottil (@usama_dev) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2264 | chaining bugs from self XSS to account takeover |
Self-XSS
WAF bypass
CSRF
Account takeover |
NA |
Behnam Yazdanpanah (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2250 | Eye for an eye: Unusual single click JWT token takeover |
Open redirect
JWT
Account takeover |
JetBrains |
Yurii Sanin (@SaninYurii) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2248 | How I can take over any user’s account with their mobile number |
Account takeover
OTP bypass
Authentication bypass |
NA |
Sushmitha Katikitala |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2240 | Facebook email disclosure and account takeover |
Information disclosure
Account takeover |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2239 | Account Takeover via XSS in e-signature feature worth 2500$ |
XSS
Account takeover |
NA |
Gökhan Güzelkokar (@gkhck_) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2219 | This is why you shouldn’t trust your Federated Identity Provider |
OAuth
Account takeover
Authentication bypass |
NA |
Soufiane Habti (@wld_basha) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2217 | Weaponizing Reflected XSS to Account Takeover |
XSS
Account takeover |
NA |
Hassan Shahid (@pwnsauc3) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2216 | A Small Tale of Account Takeover … |
IDOR
Account takeover |
NA |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2196 | Bug-Bounty | FASTMAIL [pobox.com : account takeover] |
Account takeover
Password reset |
Fastmail |
Mohammed ELdawody |
Bug Bounty | 2021-09-24 | 2023-06-13 |
2190 | Improper phone number validation to account takeover |
Logic flaw
OTP bypass
Account takeover |
NA |
shesha sai_c (@Cyb3r_4ss4s1n) |
Bug Bounty | 2021-09-27 | 2023-06-13 |
2160 | Account Takeover — Story of 2 same issues in a single program but different sub-domains. |
Account takeover |
NA |
Himanshu Pdy (@himanshu_pdy) |
Bug Bounty | 2021-10-10 | 2023-06-13 |