727 | [BAC/IDOR] How my father credit card help me to find this access control issue |
IDOR
Lack of rate limiting |
NA |
Xcoder(Joy ahmed) (@xcoder074) |
Bug Bounty | 2022-12-05 | 2023-06-13 |
711 | Scoring $$$ for a very simple bug : You don’t always need proxy tools |
IDOR |
NA |
MRD7 (@_mrd7_) |
Bug Bounty | 2022-12-10 | 2023-06-13 |
704 | How I became a millionaire in 3h | Fintech Bug Bounty — Part 1 |
IDOR
Lack of rate limiting
Logic flaw |
NA |
0x4KD (@0x4kd) |
Bug Bounty | 2022-12-12 | 2023-06-13 |
690 | Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes |
SSO
IDOR
Missing authentication |
HAwebsso.nl |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2022-12-14 | 2023-06-13 |
675 | [GraphQL IDOR]Leaking credit card information of 1000s of users |
IDOR
GraphQL |
NA |
Vipul Sahu |
Bug Bounty | 2022-12-20 | 2023-06-13 |
666 | Zero Click To Account Takeover (IDOR + XSS) |
IDOR
XSS
Account takeover |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
665 | Delete any Video or Reel on Facebook (11,250$) |
IDOR |
Meta / Facebook |
Bassem Bazzoun (@bassemmbazzoun)) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
608 | Meta Quest: Attacker could make any Oculus user to follow (subscribe) him without any approval |
IDOR
Authorization flaw |
Meta / Facebook |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
580 | How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services |
SSRF
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-01-17 | 2023-06-13 |
562 | Bypassing E2E encryption leads to multiple high vulnerabilities. |
IDOR
SSRF |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
526 | The 100+ Million Person Data Disclosure |
IDOR |
NA |
Jason Haddix (@Jhaddix) |
Bug Bounty | 2023-01-29 | 2023-06-13 |
525 | Discovered a Critical IDOR and Earned $900 for My First P1 Vulnerability! |
IDOR |
NA |
Abhisek R (@abh1sek_r) |
Bug Bounty | 2023-01-29 | 2023-06-13 |
524 | How I Found an Insecure Direct Object Reference in TikTok |
IDOR |
TikTok |
mrhavit |
Bug Bounty | 2023-01-29 | 2023-06-13 |
517 | Mass Account takeover by bypassing 2 FA |
MFA bypass
IDOR
Account takeover |
NA |
Zeeshan Mustafa (@by6153) |
Bug Bounty | 2023-01-31 | 2023-06-13 |
513 | An IDOR vulnerability often hides many others |
IDOR
GraphQL |
NA |
Allam Rachid (@blank_cold) |
Bug Bounty | 2023-02-01 | 2023-06-13 |
505 | IDOR - Inside the Session Storage |
IDOR |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
500 | Play with Google, Twitter, Apple, Dell |
XSS
HTML injection
IDOR
Information disclosure |
Google
Twitter
Apple
Dell |
rezaduty (@rezaduty) |
Bug Bounty | 2023-02-03 | 2023-06-13 |
464 | IDOR Leads to MASS Account Takeover |
IDOR
Account takeover |
NA |
Yaseen Zubair |
Bug Bounty | 2023-02-12 | 2023-06-13 |
434 | Found an URL in the android application source code which lead to an IDOR |
Android
Information disclosure
IDOR |
NA |
Vengeance |
Bug Bounty | 2023-02-18 | 2023-06-13 |
430 | Exposing 185M+ Indians’ Personal Information and much more |
Broken Access Control
IDOR
Information disclosure |
Aadhaar
CERT-In |
Robin Justin (@_robinjustin_) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
412 | Insufficient GraphQL API vulnerability due to lack of validation of Authorization Bearer token |
GraphQL
IDOR |
NA |
Int (@intlulz) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
395 | My P1 — Account Takeover |
Account takeover
IDOR
Password reset |
NA |
Kullai (@Kullai12) |
Bug Bounty | 2023-02-25 | 2023-06-13 |
368 | How a simple IDOR impacted the data of thousands of customers of an Indian automotive giant |
Account takeover
Information disclosure
IDOR |
NA |
Kushal Jain |
Bug Bounty | 2023-03-01 | 2023-06-13 |
352 | JS file enumeration for bug bounty hunters |
Information disclosure
IDOR |
NA |
Aadarsh Anand (@ScreamZoro) |
Bug Bounty | 2023-03-04 | 2023-06-13 |