594 | Bypassing authorization in Google Cloud Workstations [Google VRP] |
Account takeover
OAuth
URL validation bypass |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
587 | Account Take Over Due To AWS Cognito Misconfiguration |
Amazon cognito misconfiguration
Account takeover |
NA |
Deshine |
Bug Bounty | 2023-01-16 | 2023-06-13 |
586 | Full Account Take Over by very simple trick. |
Account takeover
Broken Access Control |
NA |
XeRox01 (@xerox0x1) |
Bug Bounty | 2023-01-16 | 2023-06-13 |
576 | From Error_Log File(P4) To Company Account Takeover(P1) and Unauthorized Actions On API |
Information disclosure |
NA |
Muhanad Israiwi (@IsrewyMohand) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
568 | The easiest way I used to bypass an admin panel |
HTTP request smuggling
Account takeover |
NA |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
561 | CSRF + Stored XSS Leading to Full Account Takeover |
Stored XSS
CSRF
Account takeover |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
553 | How i Hacked Scopely with “Sign in with Google” |
Account takeover
CORS misconfiguration
Client-side enforcement of server-side security
OAuth |
Scopely |
Ph.Hitachi |
Bug Bounty | 2023-01-23 | 2023-06-13 |
540 | Ransacking your password reset tokens |
Account takeover
Password reset
Bruteforce |
Ransack library |
Lukas Euler |
Bug Bounty | 2023-01-26 | 2023-06-13 |
517 | Mass Account takeover by bypassing 2 FA |
MFA bypass
IDOR
Account takeover |
NA |
Zeeshan Mustafa (@by6153) |
Bug Bounty | 2023-01-31 | 2023-06-13 |
497 | SSO Gadgets: Escalate (Self-)XSS to ATO |
SSO
OAuth
Account takeover
Self-XSS
Login CSRF |
NA |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2023-02-04 | 2023-06-13 |
495 | Easy Account Takeover on dell subdomain |
Password reset
Account takeover |
Dell |
Mohamed Fares (@_2os5) |
Bug Bounty | 2023-02-05 | 2023-06-13 |
480 | Chaining Bugs to get my First Bug Bounty |
CSRF
Open redirect
Clickjacking
Account takeover |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
468 | HubSpot Full Account Takeover in Bug Bounty |
Account takeover
Hyperlink injection
Password reset |
HubSpot |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
464 | IDOR Leads to MASS Account Takeover |
IDOR
Account takeover |
NA |
Yaseen Zubair |
Bug Bounty | 2023-02-12 | 2023-06-13 |
455 | Bypassing CORS configurations to produce an Account Takeover for Fun and Profit |
CORS misconfiguration
Account takeover |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
444 | Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise |
Cryptographic issues
JWT
Account takeover
Authentication bypass |
Microsoft (Azure) |
John Novak |
Bug Bounty | 2023-02-15 | 2023-06-13 |
429 | Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover |
Account takeover
SSO
OTP
Authentication bypass |
NA |
Aidil Arief |
Bug Bounty | 2023-02-20 | 2023-06-13 |
400 | Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer |
Account takeover
DOM XSS |
Microsoft (Azure) |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-02-24 | 2023-06-13 |
395 | My P1 — Account Takeover |
Account takeover
IDOR
Password reset |
NA |
Kullai (@Kullai12) |
Bug Bounty | 2023-02-25 | 2023-06-13 |
391 | Account Takeover worth of $5 |
OAuth
Account takeover |
NA |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
387 | Interesting Stored XSS in sandboxed environment to Full Account Takeover |
Stored XSS
Account takeover |
NA |
Anurag__Verma |
Bug Bounty | 2023-02-27 | 2023-06-13 |
374 | How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability? |
Account takeover
Authentication bypass |
NA |
Vivek Kumar Yadav (@0xd3vil) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
368 | How a simple IDOR impacted the data of thousands of customers of an Indian automotive giant |
Account takeover
Information disclosure
IDOR |
NA |
Kushal Jain |
Bug Bounty | 2023-03-01 | 2023-06-13 |