1929 | Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle%27s Shibboleth |
Session hijacking
Session management issue
Account takeover
RCE |
Moodle |
Johannes Moritz |
Bug Bounty | 2022-01-10 | 2023-06-13 |
1923 | C.S.T.I Lead To Account Takeover $$$ |
CSTI
Account takeover |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1894 | How I was able to take over accounts in websites deal with Github as an SSO provider |
Bruteforce
Lack of rate limiting
SSO
Email verification bypass
Account takeover |
NA |
Khaled Mohamed |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1864 | IDOR vulnerability on invoice and weak password reset leads to account take over |
IDOR
Password reset
Account takeover
Payment tampering
Logic flaw |
NA |
Damaidec |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1842 | Google Security Misconfiguration Leads to Account Takeover ! |
Logic flaw
Spoofing |
Google |
Harsh Banshpal |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1841 | Full Account takeover (ATO) — a tale of two bugs 🐛 |
IDOR
Account takeover |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1825 | A tale of 0-Click Account Takeover and 2FA Bypass. |
Account takeover
Password reset
MFA bypass |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2022-02-12 | 2023-06-13 |
1822 | Hacking AWS Cognito Misconfiguration to Zero Click Account Takeover |
AWS misconfiguration
Account takeover |
NA |
Preetham Bomma (@cyber01_) |
Bug Bounty | 2022-02-14 | 2023-06-13 |
1774 | Password Reset to Admin Access |
Account takeover
Authentication bypass
Password reset |
NA |
Jesse Clark (@Hogarth45_) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1770 | CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO |
Stored XSS
Account takeover |
Apache |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1761 | The Bad Twin: a peculiar case of JWT exploitation scenario |
Account takeover |
NA |
Sandh0t (@sandh0t) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1760 | AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service |
Cross-tenant vulnerability
Account takeover |
Microsoft |
Yanir Tsarimi (@Yanir_) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1729 | How I managed to trigger XSS automatically to get critical account takeover |
Stored XSS |
NA |
c4rrilat0r (@c4rrilat0r) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1696 | Bug Bounty Adventures: A NodeBB 0-day |
CSRF
Account takeover
SSO
Authentication flaw |
Opera |
Marouane Mouhtadi (@Mar0_0uane) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1693 | Stealing cookies from subdomain leads to takeover user accounts at redacted.com |
Account takeover
XSS |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-27 | 2023-06-13 |
1659 | How I hacked one of the biggest airlines group of the world |
IDOR
Account takeover |
NA |
Tarek Bouali (@iambouali) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1656 | New npm Flaws Let Attackers Better Target Packages for Account Takeover |
Information disclosure |
GitHub |
Yakir Kadkoda |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1652 | Watch out the links : Account takeover! |
Account takeover |
NA |
Akash Hamal (@AkashHamal0x01) |
Bug Bounty | 2022-04-06 | 2023-06-13 |
1651 | SSRF and Account Takeover via XSS in ERPNext (0-day) |
SSRF
XSS
Account takeover |
ERPNext |
huli (@aszx87410) |
Bug Bounty | 2022-04-06 | 2023-06-13 |
1649 | Multiple vulnerability leading to account takeover in TikTok SMB subdomain. |
IDOR |
TikTok |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2022-04-07 | 2023-06-13 |
1615 | Full Account Takeover via Open Redirection |
Open redirect
Token leak
Account takeover
OAuth |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-04-17 | 2023-06-13 |
1586 | ATO without any interaction [aws cognito misconfiguration] |
Account takeover
Lack of rate limiting |
GitHub |
Shreyaskoli (@SPY8OY) |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1575 | Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO) |
XSS
CSRF
Account takeover |
NA |
Zulfi Al-Farizi |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1569 | Its all about 2fa bypass, or Account Takeover |
Password reset
Account takeover
OTP bypass |
NA |
anjaneyulu kanakatla |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1562 | The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… |
CSS injection
Clickjacking
Account takeover
XSS
Cookie bomb
Self-XSS
CSRF |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2022-05-10 | 2023-06-13 |