2148 | 500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨💻 |
OTP bypass
Account takeover
Password reset |
NA |
Gowtham_Naidu (@NaiduPonnana) |
Bug Bounty | 2021-10-13 | 2023-06-13 |
2086 | From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy |
Broken Access Control
Information disclosure
IDOR
HTML injection |
Udemy |
Mostafa Mamdoh |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2083 | Privilege Escalation, worth of €300 |
Broken Access Control
IDOR
Privilege escalation |
NA |
Hemant Kumar |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2082 | Never leave this tip while you hunting Broken Access Control |
Broken Access Control |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2016 | Privilege Escalation in Microsoft Teams |
Privilege escalation
Broken Access Control |
Microsoft |
Vikas Anil Sharma (@vikzsharma) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
1993 | Broken Access Control |
IDOR |
Microsoft |
Meareg |
Bug Bounty | 2021-12-16 | 2023-06-13 |
1956 | My first Google HOF |
Broken Access Control |
Google |
RV Sharma |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1917 | 120 Days of High Frequency Hunting |
SSRF
LFI
Information disclosure
Broken Access Control
Authentication bypass
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1916 | Moodle: Blind SQL Injection (CVE-2021-36393) and Broken Access Control (CVE-2021-36397) |
SQL injection
Broken Access Control |
Moodle |
0xkasper (@0xkasper) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1914 | How i found “Broken Access Control Through out-of-sync setup” and got $1000 |
Broken Access Control
Authorization flaw |
NA |
Mr Robert | Ahmed M Hassan (@Mr_Robert20) |
Bug Bounty | 2022-01-16 | 2023-06-13 |
1844 | How can I access the members-only video comment? | YouTube ($5,000) |
Broken Access Control |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-02-07 | 2023-06-13 |
1746 | How Did I Leak 5.2k Customer Data From a Large Company? (via Broken Access Control) |
Broken Access Control |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1744 | I can see the dislikes count even though is hidden by YouTube | YouTube ($500) |
Broken Access Control
IDOR |
NA |
R ando (@Rando02355205) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1712 | Bug Bounty catches part -1 |
Authentication bypass
Information disclosure
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1711 | Broken session control leads to access private videos using the shared link even after revoking the access for specific time!! — #GoogleVRP |
Broken Access Control |
Google |
Naveenroy |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1695 | Broken Access Control - IDOR |
IDOR |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1694 | Deleting account via support ticket |
IDOR
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-26 | 2023-06-13 |
1671 | View Friends List of any users using “View as” | Facebook Bug bounty |
Logic flaw
Broken Access Control |
Meta / Facebook |
Ph.Hitachi |
Bug Bounty | 2022-04-02 | 2023-06-13 |
1660 | CloudKit Share Records leak the title of private iCloud files |
IDOR
Broken Access Control |
Apple |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1655 | CVE-2021-4119: [Bookstack] Email harvesting via SQL "LIKE" clause exploitation |
Broken Access Control
SQL injection |
Bookstack |
Haxatron (@Haxatron1) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1645 | Securing Easy Appointments and earning CVE-2022-0482 |
Broken Access Control |
Easy!Appointments |
Francesco Carlucci (@francecarlucci) |
Bug Bounty | 2022-04-09 | 2023-06-13 |
1637 | Broken session control leads to access the admin panel even after revoking the access!! — #ZOHO |
Broken Access Control |
Zoho |
Naveenroy |
Bug Bounty | 2022-04-12 | 2023-06-13 |
1618 | How I was able to see likes and dislikes count even though is hidden by victim | YouTube #4 |
Broken Access Control |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1567 | How I Paid For My Holiday With Bug Bounty |
XSS
Broken Access Control
IDOR
Unrestricted file upload |
NA |
Tobydavenn |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1548 | Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms |
Privilege escalation
Broken Access Control
Kubernetes |
Google
AWS
Microsoft
Red Hat |
Yuval Avrahami (@yuval_avrahami) |
Bug Bounty | 2022-05-17 | 2023-06-13 |