1535 | PayPal IDOR via billing Agreement Token (closed Informative, payment fraud) |
IDOR |
Paypal |
Souhaib Naceri (@h4x0r_dz) |
Bug Bounty | 2022-05-21 | 2023-06-13 |
1491 | Account Takeover by Chaining Two IDORs |
IDOR
Account takeover |
NA |
Demon (@R29k_) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1478 | How I found a Critical Bug in Instagram and Got 49500$ Bounty From Facebook |
IDOR |
Meta / Facebook |
Neeraj Sharma (@root_n33r4j) |
Bug Bounty | 2022-06-12 | 2023-06-13 |
1450 | How I hacked one of the biggest Airline in the world |
IDOR
Account takeover
Authorization flaw |
NA |
Dali Jandro (@Sazouki_) |
Bug Bounty | 2022-06-18 | 2023-06-13 |
1442 | Exploiting vulnerabilities in iOS Application |
IDOR
Bruteforce
Lack of rate limiting
Account takeover
iOS |
NA |
Raj Singh Chauhan (@raj_singh_ch) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1420 | Access control worth $2000 (everyone missed this IDOR+Access control between two admins.) |
IDOR
Broken Access Control |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1413 | My First Apple Bug And My First Writeup |
IDOR
Email verification bypass |
Apple |
Banavath Aravind (@nanicyb) |
Bug Bounty | 2022-06-29 | 2023-06-13 |
1400 | We Hacked Larksuite For 1 month and Here is what we found |
XSS
IDOR
Privilege escalation
Broken Access Control
CSRF
40x bypass |
Lark Technologies |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-07-04 | 2023-06-13 |
1398 | Exposing Millions of Voter ID card users’ details. |
IDOR
OTP bypass
Account takeover
Logic flaw |
CERT-In |
Aziz Al Aman (@nxtexploit) |
Bug Bounty | 2022-07-06 | 2023-06-13 |
1391 | PII Disclosure of Apple Users ($10k) |
IDOR
Lack of rate limiting
Bruteforce
Information disclosure |
Apple |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1386 | An interesting idor that allowed me to See all projects ($$$$ Bounty) |
IDOR |
NA |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1379 | How a Simple IDOR Led Me to Delete Any Account |
IDOR
CSRF |
NA |
rajesh.r (@_rajesh_ranjan_) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1367 | Abusing URL Shortners for fun and profit |
Information disclosure
Account takeover
IDOR |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1362 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
Lack of rate limiting
Privilege escalation
IDOR
Account takeover |
NA |
Muhammad Talha / evilmango |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1349 | Hey Google Lets submit bug from Victim Account ! |
IDOR |
Google |
Prasanth Elangovan |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1332 | I mean, IDOR is NOT only about others ID |
IDOR |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1323 | A Developer’s Nightmare: Story of a simple IDOR and some poor fixes worth $1125 |
IDOR |
NA |
Marcos IAF (@marcos_iaf) |
Bug Bounty | 2022-07-24 | 2023-06-13 |
1315 | Digging JS files to find BUGs |
IDOR
Information disclosure |
NA |
Adnan Malik (@adnanmalikinfo) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1285 | Multiple bugs in one program leads to 1500€ |
Privilege escalation
IDOR
Authorization flaw |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1235 | Bypassing unexpected IDOR |
IDOR
40x bypass |
NA |
Bharatsingh |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1221 | Business Logic Vulnerability via IDOR |
IDOR
Payment tampering |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1183 | Oracle SBC: Multiple Security Vulnerabilities Leading to Unauthorized Access and Denial of Service |
IDOR
Path traversal
DoS |
Oracle |
Harold Zang |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1173 | Break the Logic: 5 Different Perspectives in Single Page (€1500) |
Client-side enforcement of server-side security
IDOR
Authorization flaw |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-08-26 | 2023-06-13 |
1167 | The Million Dollar IDOR |
IDOR
Race condition
GraphQL |
NA |
Monish Basaniwal |
Bug Bounty | 2022-08-27 | 2023-06-13 |
1165 | Unsubscribe any user’s e-mail notifications via IDOR |
IDOR |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-28 | 2023-06-13 |