1860 | My first bounty, IDOR + Self XSS [€3000] |
Self-XSS
IDOR |
Intigriti |
Ladecruze (@ladecruze) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1843 | What I Found on Sony Vulnerability Disclosure Program |
Information disclosure
Lack of rate limiting
Open redirect
IDOR
XSS |
Sony |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-02-07 | 2023-06-13 |
1841 | Full Account takeover (ATO) — a tale of two bugs 🐛 |
IDOR
Account takeover |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1835 | Story of critical security flaws I found in Glints |
IDOR
Information disclosure |
Glints |
huli (@aszx87410) |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1834 | Oracle Server Side Request Forgery (SSRF) Metadata |
SSRF |
Oracle |
Lidor Ben Shitrit |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1817 | Trim private live videos and access them (Meta bug bounty) |
IDOR |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1769 | IDOR in support.mozilla.org through Code Review |
IDOR |
Mozilla |
Brandon Roldan |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1767 | 4300$ Instagram IDOR Bug (2022) |
IDOR |
Meta / Facebook |
Nawaf Alkhaldi (@nvmeeet) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1744 | I can see the dislikes count even though is hidden by YouTube | YouTube ($500) |
Broken Access Control
IDOR |
NA |
R ando (@Rando02355205) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1716 | Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors |
IDOR |
Microsoft |
Meareg |
Bug Bounty | 2022-03-18 | 2023-06-13 |
1715 | Adobe bug bounty using IDOR, Confidential data leaks |
IDOR |
Adobe |
Debprasad Banerjee |
Bug Bounty | 2022-03-19 | 2023-06-13 |
1710 | ($$$) Broken Authentication and IDOR at [REDACTED] |
IDOR |
NA |
Rizaldi Wahaz (@wah_haz) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1706 | Story about more than 3.5 million PII leakage in Yahoo!!! |
IDOR
Information disclosure
iOS |
Yahoo! / Verizon Media |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1695 | Broken Access Control - IDOR |
IDOR |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1694 | Deleting account via support ticket |
IDOR
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-26 | 2023-06-13 |
1660 | CloudKit Share Records leak the title of private iCloud files |
IDOR
Broken Access Control |
Apple |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1659 | How I hacked one of the biggest airlines group of the world |
IDOR
Account takeover |
NA |
Tarek Bouali (@iambouali) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1649 | Multiple vulnerability leading to account takeover in TikTok SMB subdomain. |
IDOR |
TikTok |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2022-04-07 | 2023-06-13 |
1642 | The #100DaysOfHacking Challenge : A Game Changer for Me |
IDOR |
NA |
Najam Ul Saqib (@NjmUlSqb) |
Bug Bounty | 2022-04-10 | 2023-06-13 |
1634 | IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles |
IDOR |
Drexel University |
Ahmed Hassan |
Bug Bounty | 2022-04-12 | 2023-06-13 |
1568 | P1 Bug — PII information disclosure |
Information disclosure
IDOR |
NA |
Huntersherlock |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1567 | How I Paid For My Holiday With Bug Bounty |
XSS
Broken Access Control
IDOR
Unrestricted file upload |
NA |
Tobydavenn |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1558 | Takeover seller accounts worth billions & millions |
IDOR
Account takeover |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-05-12 | 2023-06-13 |
1545 | A Tale of Confusing IDOR |
IDOR |
TikTok |
Avi (@_naaash_) |
Bug Bounty | 2022-05-18 | 2023-06-13 |
1541 | How I was able to access IBM internal documents |
Information disclosure
IDOR |
IBM |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2022-05-19 | 2023-06-13 |