Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
444
Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise
Cryptographic issues
JWT
Account takeover
Authentication bypass
Microsoft (Azure)
John Novak
Bug Bounty
2023-02-15
2023-06-13
357
GitHub Security Lab audited DataHub: Here’s what they found
SSRF
Insecure deserialization
Cypher injection
Authentication bypass
Authorization bypass
XSS
Open redirect
JWT
JSON injection
Cryptographic issues
Session expiration issue
Security code review
DataHub
Alvaro Muñoz (@pwntester)
Bug Bounty
2023-03-03
2023-06-13
324
Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover
Authorization bypass
JWT
Account takeover
Microsoft (ClipChamp)
Vikas Anil Sharma (@vikzsharma)
Bug Bounty
2023-03-10
2023-06-13
196
From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR
Debug mode enabled
IDOR
Information disclosure
JWT
Broken Access Control
Exposed registration page
NA
Aayush Vishnoi (@AayushVishnoi10)
Bug Bounty
2023-04-14
2023-06-13
124
Privilege Escalations through Integrations
Privilege escalation
Amazon cognito misconfiguration
JWT
Account takeover
NA
Colin McQueen
Bug Bounty
2023-05-04
2023-06-13
103
What is kong & why we’re relying on it
RCE
Sandbox escape
Authentication bypass
Hardcoded credentials
Broken Access Control
Privilege escalation
JWT
Konga
Laluka (@TheLaluka)
Bug Bounty
2023-05-10
2023-06-13
« Previous
1
2