1558 | Takeover seller accounts worth billions & millions |
IDOR
Account takeover |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-05-12 | 2023-06-13 |
1556 | Forging OAuth tokens using discovered client id and client secret |
Information disclosure
Account takeover |
NA |
Basyouni (@AshrafBasyoni4) |
Bug Bounty | 2022-05-12 | 2023-06-13 |
1555 | From android app to access admin dashboard |
Exposed registration page
Account takeover |
NA |
Oday Alhalabi (@OdayAlhalabi) |
Bug Bounty | 2022-05-13 | 2023-06-13 |
1551 | Hacking Swagger-UI - from XSS to account takeovers |
DOM XSS
Account takeover |
Shopify
Paypal
GitLab
Atlassian
Yahoo! / Verizon Media
Microsoft
Jamf |
Dawid Moczadło (@kannthu1) |
Bug Bounty | 2022-05-16 | 2023-06-13 |
1549 | Stealing Google Drive OAuth tokens from Dropbox |
CSRF
SSRF
Account takeover |
Dropbox |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2022-05-17 | 2023-06-13 |
1542 | From Wayback to Account Takeover |
Information disclosure
Account takeover |
Plex |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2022-05-19 | 2023-06-13 |
1537 | Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web |
Account takeover
Pre-hijacking attack |
Dropbox
Meta / Facebook
LinkedIn
WordPress
Zoom |
Avinash Sudhodanan (@sudoavi) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1519 | How an Open Redirection Leads to an Account Takeover? |
Open redirect
Account takeover |
NA |
Mahendra Purbia (@Mah3Sec_) |
Bug Bounty | 2022-05-26 | 2023-06-13 |
1512 | Exploiting iOS app for fun and profit |
Account takeover
Information disclosure |
NA |
Bijan Murmu (@0xbijan) |
Bug Bounty | 2022-05-29 | 2023-06-13 |
1491 | Account Takeover by Chaining Two IDORs |
IDOR
Account takeover |
NA |
Demon (@R29k_) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1472 | 500$ Account Takeover |
Account takeover
Information disclosure
HTTP response manipulation |
Xsolla |
Hemant Kumar |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1454 | CSRF leads to account takeover in Yahoo! |
CSRF
Account takeover |
Yahoo! / Verizon Media |
Retr02332 (@Retr02332) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1450 | How I hacked one of the biggest Airline in the world |
IDOR
Account takeover
Authorization flaw |
NA |
Dali Jandro (@Sazouki_) |
Bug Bounty | 2022-06-18 | 2023-06-13 |
1448 | Account Takeover by OTP bypass |
Information disclosure
Client-side enforcement of server-side security
OTP bypass
Account takeover |
NA |
Vaibhav Kumar Srivastava |
Bug Bounty | 2022-06-19 | 2023-06-13 |
1442 | Exploiting vulnerabilities in iOS Application |
IDOR
Bruteforce
Lack of rate limiting
Account takeover
iOS |
NA |
Raj Singh Chauhan (@raj_singh_ch) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1405 | Admin account takeover via weird Password Reset Functionality |
Account takeover
Authentication bypass
Password reset |
NA |
Mahmoud Youssef (@0xmahmoudjo0) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1402 | ($$$) Origin ip to account takeover |
WAF bypass
Password reset
Host header injection
Account takeover |
NA |
Hemant Kumar |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1398 | Exposing Millions of Voter ID card users’ details. |
IDOR
OTP bypass
Account takeover
Logic flaw |
CERT-In |
Aziz Al Aman (@nxtexploit) |
Bug Bounty | 2022-07-06 | 2023-06-13 |
1395 | Account hijacking using "dirty dancing" in sign-in OAuth-flows |
OAuth
Account takeover |
NA |
Frans Rosén (@fransrosen) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1390 | Account Takeover via Response Manipulation |
Authentication bypass
Account takeover
MFA bypass
HTTP response manipulation |
NA |
BUG HUNTER |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1385 | Exploiting SQL Injection at Authorization token |
SQL injection
Account takeover |
NA |
Basudev |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1367 | Abusing URL Shortners for fun and profit |
Information disclosure
Account takeover
IDOR |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1362 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
Lack of rate limiting
Privilege escalation
IDOR
Account takeover |
NA |
Muhammad Talha / evilmango |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1359 | Authorization token leak from verify email endpoint |
Account takeover
Information disclosure |
NA |
Vengeance |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1355 | CRLF to Account takeover (chaining bugs) |
CRLF injection
XSS
Account takeover |
NA |
MoSec (@moe1n1) |
Bug Bounty | 2022-07-16 | 2023-06-13 |