Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4201Google Groups Authorization Bypass Authorization flaw Google Daniel Marad Bug Bounty2019-04-152023-06-13
4192Responsible disclosure: improper access control in Gitlab private project. Authorization flaw GitLab Riccardo Padovani (@rpadovani93) Bug Bounty2019-04-192023-06-13
4178Missing Authorization check while deleting App Review for Marketing API Authorization flaw Meta / Facebook Family guy Bug Bounty2019-04-252023-06-13
4172Broken Access: Posting to Google private groups through any user in the group Authorization flaw Google Elber Andre (@Elber333) Bug Bounty2019-04-272023-06-13
4168Reply To Instagram Stories where privacy of who can reply is set to Nobody’. Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-04-302023-06-13
4142Google Adwords(Privilege Escalation): Read-only user able to add YouTube channels via Linked accounts Privilege escalation Authorization flaw Google Family guy Bug Bounty2019-05-212023-06-13
4135Multiple API issues due to Fixed Authorization token. Authorization flaw NA Mustafa Khan (@by6153) Bug Bounty2019-05-242023-06-13
4125Missing access control at play store Authorization flaw Google Vishwaraj Bhattrai (@vishwaraj101) Bug Bounty2019-06-032023-06-13
4111Chaining Improper Authorization To Race Condition To Harvest Credit Card Details : A Bug Bounty Story Authorization flaw Race condition NA Mandeep Jadon (@1337tr0lls) Bug Bounty2019-06-132023-06-13
4093Business user Employees could have applied block list to all ad accounts listed in the business manager. Authorization flaw Logic flaw Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2019-06-172023-06-13
4081Page Admin Disclosure | Facebook Bug Bounty 2019 Authorization flaw Meta / Facebook Ajay Gautam (@evilboyajay) Bug Bounty2019-06-222023-06-13
4069Facebook BugBounty : Short story on Page admin disclosure Authorization flaw Privilege escalation Meta / Facebook Bijan Murmu (@0xBijan) Bug Bounty2019-06-282023-06-13
4053A malicious editor of a page can support to a community action which can’t be unsupported by the admin! Authorization flaw Meta / Facebook mAshraf Bug Bounty2019-07-092023-06-13
4045Hacking intoTinder’s Premium Model Authorization flaw Tinder Sanskar Jethi (@sansyrox) Bug Bounty2019-07-142023-06-13
4041Facebook Bug : Sending messages as a page with jobmanager permission Authorization flaw Privilege escalation Meta / Facebook Devansh batham (@devanshwolf) Bug Bounty2019-07-152023-06-13
4004Reposted [2019]: Hacking YouTube for #fun and #profit Authorization flaw Google Alexandru Coltuneac (@dekeeu) Bug Bounty2019-07-302023-06-13
3971ByPassing fix of Domain Blocking feature in Business Manager Authorization flaw Logic flaw Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2019-08-152023-06-13
3966Facebook Bug Bounty: Reading WhatsApp contacts list without unlocking the device Authorization flaw Meta / Facebook Arvind (@ar_arv1nd) Bug Bounty2019-08-192023-06-13
3963How I made my first $$$ from finding a bug in Facebook Authorization flaw Meta / Facebook Aayush Pokhrel (@aayushpok) Bug Bounty2019-08-212023-06-13
3962Sending Message as page being an analyst/ advertiser? Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-08-212023-06-13
3943Add new user with Admin permission and takeover the organization Authorization flaw Privilege escalation NA Tarek Mohamed (@Conan0x3) Bug Bounty2019-09-042023-06-13
3882Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts. Authorization flaw Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2019-10-122023-06-13
3841Bug Bounty: Broken API Authorization Authorization flaw NA Th3hidd3nmist (@th3_hidd3n_mist) Bug Bounty2019-11-122023-06-13
3829Bypassing the patch for my previous Instagram bug. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-182023-06-13
3818Reply To Instagram Stories where privacy of who can reply is set to Nobody’. (Part 2) Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-212023-06-13