2148 | 500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨💻 |
OTP bypass
Account takeover
Password reset |
NA |
Gowtham_Naidu (@NaiduPonnana) |
Bug Bounty | 2021-10-13 | 2023-06-13 |
2053 | Account Takeover in $Million Company? |
Account takeover
Password reset |
Fastmail |
0xGodson (@0xGodson_) |
Bug Bounty | 2021-11-24 | 2023-06-13 |
2000 | Zero Click To Account Takeover |
Account takeover
Password reset |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2021-12-14 | 2023-06-13 |
1945 | P5 to P1: Interesting Account Takeover |
Account takeover
Session expiration issue
Password reset |
NA |
Tushar Sharma (@tusharSharma_0) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1941 | thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality |
IDOR
Password reset
Account takeover |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1932 | Host Header Injection Lead To Account Takeovers |
Host header injection
Password reset
Account takeover |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2022-01-09 | 2023-06-13 |
1864 | IDOR vulnerability on invoice and weak password reset leads to account take over |
IDOR
Password reset
Account takeover
Payment tampering
Logic flaw |
NA |
Damaidec |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1825 | A tale of 0-Click Account Takeover and 2FA Bypass. |
Account takeover
Password reset
MFA bypass |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2022-02-12 | 2023-06-13 |
1774 | Password Reset to Admin Access |
Account takeover
Authentication bypass
Password reset |
NA |
Jesse Clark (@Hogarth45_) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1749 | Rate Limit Bypass at Readme.com |
Lack of rate limiting
Password reset |
Readme.com |
Girishbo |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1627 | Bypass Rate Limit — A blank space leads to this random encounter! |
Password reset
Rate limiting bypass |
NA |
Roxst4r (@mveswar98) |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1602 | How I Bypassed 2FA while Resetting Password |
MFA bypass
Password reset |
NA |
Sufiyan Gouri (@gouri_sufyan) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1569 | Its all about 2fa bypass, or Account Takeover |
Password reset
Account takeover
OTP bypass |
NA |
anjaneyulu kanakatla |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1540 | Gaining access through error-based SQLi using WebSockets |
SQL injection
Websockets
Password reset |
NA |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-01-12 | 2023-06-13 |
1405 | Admin account takeover via weird Password Reset Functionality |
Account takeover
Authentication bypass
Password reset |
NA |
Mahmoud Youssef (@0xmahmoudjo0) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1402 | ($$$) Origin ip to account takeover |
WAF bypass
Password reset
Host header injection
Account takeover |
NA |
Hemant Kumar |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1236 | UN United Nations Host Header Injection leads to any Full Account Takeover (ATO) |
Host header injection
Password reset
Account takeover |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1219 | We discovered major vulnerabilities in Control Web Panel. Here’s how we found them. |
Path traversal
RCE
Weak crypto
Password reset
Account takeover |
Centos Web Panel (CWP) |
Immersive Labs (@immersivelabs) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1199 | Account takeover worth $1000 |
Account takeover
Authentication bypass
Information disclosure
Password reset |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1067 | Android Application Forgot Password Token Leakage Leading to Account Takeover |
Information disclosure
Password reset
Account takeover
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1003 | Bugcrowd — Tale of multiple misconfigurations!! ❌ |
Account takeover
OAuth
OTP bypass
Password reset |
NA |
Vaibhav Lakhani |
Bug Bounty | 2022-10-04 | 2023-06-13 |
975 | In GUID We Trust |
IDOR
Password reset
Race condition
Account takeover |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2022-10-11 | 2023-06-13 |
894 | AWS SSRF to Root on production instance — A bug worth 1.75Lacs |
SSRF
RCE
Password reset |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
540 | Ransacking your password reset tokens |
Account takeover
Password reset
Bruteforce |
Ransack library |
Lukas Euler |
Bug Bounty | 2023-01-26 | 2023-06-13 |