3700 | Tale of a Misconfiguration in Password Reset |
Password reset
Information disclosure |
NA |
Naveenroy |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3653 | Tale of Account Takeovers (Part-1) |
Account takeover
HTTP parameter pollution
Password reset
OTP bypass |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-02-22 | 2023-06-13 |
3607 | User%27s email disclosure via invalid password reset link [$250] |
Password reset
Information disclosure |
NA |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-03-13 | 2023-06-13 |
3603 | How I earned $800 for Host Header Injection Vulnerability |
Host header injection
Password reset |
NA |
Pethuraj (@Pethuraj) |
Bug Bounty | 2020-03-15 | 2023-06-13 |
3567 | Account Take Over without user Interaction |
Password reset
Information disclosure
Account takeover |
NA |
Ravilla Bharath |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3562 | Playing with JSON Web Tokens for Fun and Profit |
Password reset
Email verification bypass |
NA |
Muhammad Qasim Munir (@MeetAn0nym0us) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3552 | How i Unlocked the blocked accounts? |
Password reset
HTTP parameter pollution
IDOR |
NA |
Maria Zulfiqar |
Bug Bounty | 2020-04-11 | 2023-06-13 |
3483 | Weak Cryptography in Password Reset to Full Account Takeover |
Account takeover
Password reset
Cryptographic issues |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-05-15 | 2023-06-13 |
3481 | Password Reset Poisoning leading to Account Takeover |
Password reset
Account takeover |
NA |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2020-05-16 | 2023-06-13 |
3471 | Multiple flaws leads to Account Takeover within an Application |
Account takeover
Password reset |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3360 | How I was able to take over any account via the Password Reset Functionality. |
Password reset
Account takeover |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3284 | A $5000 Account Takeover |
Account takeover
Password reset |
NA |
neelam |
Bug Bounty | 2020-07-25 | 2023-06-13 |
3255 | Multi-factor Auth Bypass with Password Reset Function |
MFA bypass
Password reset
Account takeover |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-08-02 | 2023-06-13 |
3252 | Account takeover in cups.mail.ru |
Logic flaw
Password reset
Account takeover |
Mail.ru |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-08-03 | 2023-06-13 |
3249 | How I was able to do Mass Account Takeover[Bug Bounty] |
Account takeover
Password reset |
NA |
Not Rickyy (@RickyyNot) |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3203 | Fun with header and forget password, with a twist: |
Password reset
Host header injection |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-18 | 2023-06-13 |
3193 | Account Takeover For The Win 🏆 |
Account takeover
Authentication flaw
Password reset |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-08-24 | 2023-06-13 |
3107 | ATO via Host Header Poisoning |
Host header injection
Account takeover
Password reset |
NA |
Shivam Kamboj Dattana (@sechunt3r) |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3045 | Chaining password reset link poisoning, IDOR, and information leakage to achieve account takeover at api.redacted.com |
HTTP header injection |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3031 | Account takeover through password reset |
Account takeover
Password reset |
NA |
Omar Hamdy (@seaman00o) |
Bug Bounty | 2020-11-14 | 2023-06-13 |
2995 | Chaining vulnerabilities lead to account takeover |
Account takeover
Password reset
Open redirect
Lack of rate limiting |
NA |
Ahmed (@ahzsec) |
Bug Bounty | 2020-12-01 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2864 | $500 For No Rate Limit On Forgot Password Page |
Lack of rate limiting
Password reset |
NA |
BBHC (@community_bug) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2770 | Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) |
Host header injection
Account takeover
Password reset |
Niteflirt |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-02-25 | 2023-06-13 |