1596 | [EN] Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS |
Stored XSS
Mass assignment
Security code review |
pass Culture |
Aethlios (@AethliosIK) |
Bug Bounty | 2022-04-26 | 2023-06-13 |
1595 | Azure Monitor – Malicious KQL Query |
Privilege escalation
Cloud |
Microsoft |
Joosua Santasalo (@SantasaloJoosua) |
Bug Bounty | 2022-04-27 | 2023-06-13 |
1594 | Bypassing WAF for $2222 |
WAF bypass
Path traversal |
NA |
Divyansh Sharma |
Bug Bounty | 2022-04-27 | 2023-06-13 |
1593 | Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054) |
SSRF |
VMware |
Keiran Sampson (@hpy_downunder) |
Bug Bounty | 2022-04-27 | 2023-06-13 |
1592 | 2FA Secret value disclosure leads to 2FA Bypass - Bug Bounty Writeup |
MFA bypass
Information disclosure |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1591 | Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL |
Cross-tenant vulnerability
Privilege escalation
Authentication bypass
Cloud |
Microsoft |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1590 | Contact Point Deanonymization Vulnerability in Meta |
Information disclosure |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1589 | Exploitation of an SSRF vulnerability against EC2 IMDSv2 |
SSRF |
NA |
Yassine Aboukir (@Yassineaboukir) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1588 | Sensitive Data Exfiltration through XSS ($450) |
Token leak |
NA |
Zulfi Al-Farizi |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1587 | Page Admin Disclosure when Posting a Reel |
Spoofing |
Meta / Facebook |
Syd Ricafort (@devsyd11) |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1586 | ATO without any interaction [aws cognito misconfiguration] |
Account takeover
Lack of rate limiting |
GitHub |
Shreyaskoli (@SPY8OY) |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1585 | Vulnerable GitHub Actions Workflows Part 2: Actions That Open the Door to CI/CD Pipeline Attacks |
Privilege escalation
CI/CD |
NA |
Noam Dotan |
Bug Bounty | 2022-05-02 | 2023-06-13 |
1584 | How I got a lousyT-Shirt from the Dutch Government. |
Old components with known vulnerabilities |
Dutch Government |
Mava (@mava656) |
Bug Bounty | 2022-05-03 | 2023-06-13 |
1583 | CVE-2022-25262 | JetBrains Hub single-click SAML response takeover |
Authorization flaw
SAML
OAuth |
JetBrains |
Yurii Sanin (@SaninYurii) |
Bug Bounty | 2022-05-03 | 2023-06-13 |
1582 | Hacking a Bank by Finding a 0day in DotCMS |
Directory traversal
Unrestricted file upload
RCE |
NA |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-05-03 | 2023-06-13 |
1581 | [UNPATCHED] Cli: gh run download implementation allows overwriting git repository configuration upon artifacts downloading |
RCE |
GitHub |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1580 | How i found a vulnerability that leads to access any users’ sensitive data and got $500 |
Information disclosure |
Flickr |
Mr Robert | Ahmed M Hassan (@Mr_Robert20) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1579 | Business Logic Errors - Art of Testing Cards |
Payment bypass
Logic flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1578 | Remotely permanent crash any Instagram user via permanent DoS in user DM%27s. |
DoS |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1577 | Samsung Flow - Any App Can Read The External Storage |
Android
Insecure intent |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1576 | Samsung Galaxy - Any App Can Install Any App In The Galaxy App Store |
Android
Insecure intent |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1575 | Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO) |
XSS
CSRF
Account takeover |
NA |
Zulfi Al-Farizi |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1574 | CVE-2022-0540 - Authentication bypass in Seraph |
Authentication bypass |
NA |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1573 | How We hacked (bypassed) Admin Panel just by JS file |
Information disclosure |
NA |
Zhenwar Hawlery (@zhenwarx) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1572 | Advanced sqlmap Case Study |
SQL injection |
NA |
Peter M (@h1pmnh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |