3615 | How I was able to bypass the current password? |
Account takeover
CSRF |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3595 | Hacking — Always Check the Cross-domain Policy |
SOP bypass
CSRF |
Starbucks |
Jack |
Bug Bounty | 2020-03-19 | 2023-06-13 |
3589 | Self XSS to Account Takeover |
Account takeover
XSS
CSRF |
NA |
Ch3ckM4te |
Bug Bounty | 2020-03-24 | 2023-06-13 |
3566 | Always escalate! From Self-XSS to Persistent XSS on Login Portal |
Self-XSS
CSRF |
NA |
Phuriphat Boontanon (@zanezenzane) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3559 | How a Simple CSRF Attack Turned into a P1 Level Bug |
CSRF
Account takeover |
NA |
Lady Secspeare (@bejuveria_) |
Bug Bounty | 2020-04-05 | 2023-06-13 |
3540 | CSRF to RCE bug chain in Prestashop v1.7.6.4 and below |
RCE
CSRF
Stored XSS
Unrestricted file upload |
PrestaShop |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3516 | Account taken over in style !!! |
Logic flaw
CSRF
Account takeover |
NA |
kishore hariram (@kishorehariram) |
Bug Bounty | 2020-04-30 | 2023-06-13 |
3474 | Cors Blimey: The power of chaining CORS |
CORS misconfiguration
Stored XSS
CSRF |
NA |
Hazana (@hazanasec) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3432 | How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? |
Self-XSS
CSRF |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2020-06-01 | 2023-06-13 |
3414 | How i earned $500 from google by change one character . |
CSRF |
Google |
Oday Alhalbe |
Bug Bounty | 2020-06-06 | 2023-06-13 |
3400 | Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D |
CSRF |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-06-12 | 2023-06-13 |
3339 | CSRF Attack!!! |
CSRF |
NA |
Bala Praneeth (@Begin_hunt) |
Bug Bounty | 2020-07-04 | 2023-06-13 |
3338 | EN | Account Takeover and Sensitive Data Leakage via CORS Misconfiguration |
CORS misconfiguration
CSRF
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-07-04 | 2023-06-13 |
3316 | Tenda AC15 AC1900 Vulnerabilities Discovered and Exploited |
CSRF
XSS
Hardcoded credentials
RCE |
Tenda |
Sanjana Sarda |
Bug Bounty | 2020-07-10 | 2023-06-13 |
3276 | CSRF + Open Redirect To Account Takeover |
CSRF
Open redirect
Account takeover |
NA |
R29k (@R29k_) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3267 | Zoom Security Exploit – Cracking private meeting passwords |
CSRF
Lack of rate limiting |
Zoom |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3257 | Refocusing in bug hunting, Bonus: An interestingly simple to test CSRF bypass |
CSRF |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-01 | 2023-06-13 |
3247 | CSRF PoC mistake that broke crucial functions for the end user/victim |
Logic flaw |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3223 | Journey to my First Bug Hunt$$$$ |
CSRF |
NA |
Bala Praneeth (@Begin_hunt) |
Bug Bounty | 2020-08-13 | 2023-06-13 |
3183 | Unhiding the hidden |
Client-side enforcement of server-side security
Authorization flaw
CSRF |
NA |
I am Broot |
Bug Bounty | 2020-08-31 | 2023-06-13 |
3171 | My first bug in google and how i got CSRF token for victim account rather than bypass it ($1337)! |
CSRF |
Google |
Oday Alhalbe |
Bug Bounty | 2020-09-07 | 2023-06-13 |
3154 | My First Bug Bounty From Bug Bounty Platform redstorm.io |
CSRF |
RedStorm |
Novan Aziz Ramadhan (@novan_rmd) |
Bug Bounty | 2020-09-17 | 2023-06-13 |
3111 | Research: The mass CSRFing of *.google.com/* products. |
CSRF |
Google |
Missoum Said (@missoum1307) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3094 | Weaponizing XSS For Fun & Profit |
XSS
CSRF |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2020-10-14 | 2023-06-13 |
2990 | Site Wide CSRF On Glassdoor |
CSRF |
Glassdoor |
Tabahi (@_tabahi) |
Bug Bounty | 2020-12-03 | 2023-06-13 |