3882 | Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts. |
Authorization flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-10-12 | 2023-06-13 |
3816 | Disable Any Unconfirmed Account in Facebook |
Bruteforce |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-11-21 | 2023-06-13 |
3771 | #BugBounty — How Snapdeal (India’s Popular E-commerce Website) Kept their Users Data at Risk! |
Insecure storage of sensitive information |
Snapdeal |
Nanda Kumar (@nk00_nk) |
Bug Bounty | 2019-12-19 | 2023-06-13 |
3761 | Airbnb : Steal Earning of Airbnb hosts by Adding Bank Account/Payment Method (IDOR) |
IDOR |
Airbnb |
Vijay Kumar (@IndoAppSec) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3713 | Facebook Vulnerability: Hidden “Community Manager” in Pages due to “Invitation Accept” logic |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3577 | OTP Bruteforce- Account Takeover |
OTP bruteforce
Account takeover |
NA |
Ranjit Kumar |
Bug Bounty | 2020-03-29 | 2023-06-13 |
3544 | OTP Verification Bypass |
OTP bypass |
NA |
Kanhaiya Kumar Singh |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3535 | Exploiting a Race Condition Vulnerability |
Race condition |
NA |
Vivek Kumar Singh (@v7nc3nz) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3506 | Private Dashboards were accessible by other Admins in Analytics Dashboard |
Authorization flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-05-02 | 2023-06-13 |
3493 | $20000 Facebook DOM XSS |
DOM XSS |
Meta / Facebook |
Vinoth Kumar (@vinodsparrow) |
Bug Bounty | 2020-05-07 | 2023-06-13 |
3421 | [IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty |
IDOR |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3182 | Page shops with a hidden Product in “Featured product section” which could be controlled by attacker (Ex Editor). |
Logic flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-08-31 | 2023-06-13 |
3136 | PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover |
IDOR
Information disclosure |
NA |
Pradeep Kumar (@Killer007p) |
Bug Bounty | 2020-09-25 | 2023-06-13 |
3063 | How i got 7000$ in Bug-Bounty for my Critical Finding. |
Information disclosure |
NA |
Kishan Kumar / Noobie BoY (@hst_kishan) |
Bug Bounty | 2020-10-31 | 2023-06-13 |
3058 | Reveal the page admin that uploaded a video on the page in comment section |
Information disclosure
Logic flaw |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2020-11-02 | 2023-06-13 |
3055 | Delete Any Photos In Facebook |
Authorization flaw
Logic flaw |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2020-11-04 | 2023-06-13 |
2945 | Chaining CORS by Reflected xss to Account takeover #My first Blog |
CORS misconfiguration
Reflected XSS
Account takeover |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2888 | Strange Admin Panel Bypass Story | | Bug Bounty |
Authentication bypass
Account takeover |
NA |
Ranjeet Kumar Singh (@geekboyranjeet) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2865 | Finding SSRF BY Full Automation |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2851 | Android apk leaks access token to takeover the whole infrastructure |
Information disclosure
Hardcoded credentials
Android |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2727 | Finding Basic Authtoken in JAVASCRIPT file BY Full Automation |
Information disclosure |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2656 | Chaining an Blind SSRF bug to Get an RCE |
Blind SSRF
RCE |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-07 | 2023-06-13 |
2628 | Unauthorized access to admin setpassword page BY bypassing 403 Forbidden |
Authorization flaw |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2612 | AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug |
SSRF
Open redirect |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-24 | 2023-06-13 |
2587 | Chaining CSRF with XSS to deactivate Mass user accounts by single click |
CSRF
XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-02 | 2023-06-13 |