1154 | IDOR at Login function leads to leak user’s PII data |
IDOR
Information disclosure |
NA |
Eslam Akl (@eslam3kll) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1138 | Viewing Instagram live streams anonymously without notifying the host |
IDOR
Logic flaw
Privacy issue |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1135 | How I found my first SSRF to RCE! |
IDOR
SSRF
RCE |
NA |
Md. Asif Hossain (@0x0asif) |
Bug Bounty | 2022-09-04 | 2023-06-13 |
1129 | IDOR “Insecure direct object references”, my first P1 in Bugbounty |
IDOR |
NA |
jedus0r |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1062 | Tag Myself in Your Favorite TikTok Artist Video [IDOR] |
IDOR |
TikTok |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1061 | 7,500$ – IDOR on Apple [consultants.apple.com] |
IDOR |
Apple |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
988 | Insecure Comments |
IDOR
Authorization flaw |
Microsoft |
Meareg |
Bug Bounty | 2022-10-07 | 2023-06-13 |
975 | In GUID We Trust |
IDOR
Password reset
Race condition
Account takeover |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2022-10-11 | 2023-06-13 |
973 | Critical IDOR Vulnerability on Medium? |
IDOR |
NA |
zer0d |
Bug Bounty | 2022-10-12 | 2023-06-13 |
962 | Fall account takeover via Amazon Cognito misconfiguration |
IDOR
Account takeover |
NA |
Hossam Ahmed (@iknowhatodo0x01) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
934 | FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer |
CSTI
Stored XSS |
Microsoft |
Lidor Ben Shitrit |
Bug Bounty | 2022-10-19 | 2023-06-13 |
924 | Google VRP — [Insecure Direct Object Reference] $3133.70 |
IDOR |
Google |
Caesar Evan Santoso |
Bug Bounty | 2022-10-20 | 2023-06-13 |
923 | $1,000+ P1: PII Disclosure W/ IDOR |
IDOR |
NA |
Graham Zemel (@grahamzemel) |
Bug Bounty | 2022-10-21 | 2023-06-13 |
859 | IDOR on Unsubscribe emails to $200 bounty. |
IDOR |
NA |
shbugger1 |
Bug Bounty | 2022-11-06 | 2023-06-13 |
853 | Some Tips to Finding IDORs more easily and Fixing them |
IDOR |
NA |
Xenon |
Bug Bounty | 2022-11-08 | 2023-06-13 |
847 | Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd |
IDOR |
Google |
Caesar Evan Santoso |
Bug Bounty | 2022-11-10 | 2023-06-13 |
820 | The Story Of A Strange / Stored IDOR. |
IDOR |
NA |
Hassan Farooq |
Bug Bounty | 2022-11-16 | 2023-06-13 |
819 | Account Takeover Worth of $2500 |
Account takeover
IDOR |
NA |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-11-16 | 2023-06-13 |
778 | Able to Mass-change profile section leads to my first $BOUNTY$ |
HTML injection
IDOR
CSRF |
NA |
SYRINE |
Bug Bounty | 2022-11-25 | 2023-06-13 |
775 | How I hacked into a government e-learning website |
IDOR
Account takeover |
NA |
iamgk808 (@iamgk808) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
772 | A great weekend hack(worth $8k) |
SQL injection
IDOR
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
771 | [Hacking Bank] The Second Story of Finding Critical Vulnerabilities on Banking Application |
Android
Hardcoded credentials
IDOR |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-11-26 | 2023-06-13 |
769 | Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames |
IDOR
Broken Access Control
Android
IoT |
Ourphoto |
Nick M (@1oopho1e) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
739 | Hacking on a plane: Leaking data of millions and taking over any account |
IDOR |
NA |
rez0 (@rez0__) |
Bug Bounty | 2022-12-02 | 2023-06-13 |
737 | 3 Step IDOR in HackerResume |
IDOR |
HackerResume |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2022-12-03 | 2023-06-13 |