3811 | CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] |
CORS misconfiguration
Open redirect
Reflected XSS
Session management issue |
NA |
Mashoud1122 (@mashoud1122) |
Bug Bounty | 2019-11-24 | 2023-06-13 |
3806 | Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge |
Reflected XSS
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3777 | Stored Iframe Injection + CSRF = Account Takeover 😎😎 |
HTML injection
CSRF |
NA |
Rounak Dhadiwal (@XploiteR_D) |
Bug Bounty | 2019-12-16 | 2023-06-13 |
3770 | Account Takeover Through Password Reset Poisoning |
Password reset
Account takeover |
NA |
Vishal Bharad |
Bug Bounty | 2019-12-19 | 2023-06-13 |
3768 | Full Account Takeover (Android Application) |
Information disclosure
Account takeover |
NA |
Vishal Bharad |
Bug Bounty | 2019-12-21 | 2023-06-13 |
3764 | CSRF Token Bypasss — A Tale of my $2k bug |
CSRF
Account takeover |
NA |
Adeyefa Oluwatoba (@adeyefa_codes) |
Bug Bounty | 2019-12-23 | 2023-06-13 |
3738 | Account takeover via HTTP Request Smuggling |
HTTP request smuggling
Account takeover
Open redirect
Internal header disclosure |
NA |
hipotermia (@_hipotermia_) |
Bug Bounty | 2020-01-03 | 2023-06-13 |
3723 | How I discovered an interesting account takeover flaw? |
Account takeover
Password reset
Lack of rate limiting |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2020-01-14 | 2023-06-13 |
3714 | User Account Takeover via Signup Feature | Bug Bounty POC |
Account takeover
Logic flaw
Authorization flaw |
NA |
Muzammil Kayani (@muzammilabbas2) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3682 | Using CSRF I Got Weird Account Takeover |
CSRF
Account takeover |
NA |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3669 | A Simple IDOR to Account Takeover |
IDOR
Account takeover |
NA |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2020-02-11 | 2023-06-13 |
3653 | Tale of Account Takeovers (Part-1) |
Account takeover
HTTP parameter pollution
Password reset
OTP bypass |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-02-22 | 2023-06-13 |
3648 | Mail.Ru Ext.B Scope Account Takeover [ $1500 ] |
Account takeover
OAuth |
Mail.ru |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3639 | Account Hijack using Authorization bypass $$$$ |
Account takeover
Authorization flaw |
NA |
Bhavesh Thakur (@Bhavesh_Thakur_) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3627 | Got *Bounty* with Account takeover (ATO ) Unicode-Case Mapping Collision ! |
Account takeover |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2020-03-05 | 2023-06-13 |
3615 | How I was able to bypass the current password? |
Account takeover
CSRF |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3589 | Self XSS to Account Takeover |
Account takeover
XSS
CSRF |
NA |
Ch3ckM4te |
Bug Bounty | 2020-03-24 | 2023-06-13 |
3583 | Account Takeover Flow In Mail.ru s Ext.A Domain [ $150 ] |
Logic flaw
Account takeover |
NA |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-03-26 | 2023-06-13 |
3577 | OTP Bruteforce- Account Takeover |
OTP bruteforce
Account takeover |
NA |
Ranjit Kumar |
Bug Bounty | 2020-03-29 | 2023-06-13 |
3567 | Account Take Over without user Interaction |
Password reset
Information disclosure
Account takeover |
NA |
Ravilla Bharath |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3559 | How a Simple CSRF Attack Turned into a P1 Level Bug |
CSRF
Account takeover |
NA |
Lady Secspeare (@bejuveria_) |
Bug Bounty | 2020-04-05 | 2023-06-13 |
3522 | Beware of the GIF: Account Takeover Vulnerability in Microsoft Teams |
Account takeover
Subdomain takeover |
Microsoft |
Omer Tsarfati (@OmerTsarfati) |
Bug Bounty | 2020-04-27 | 2023-06-13 |
3516 | Account taken over in style !!! |
Logic flaw
CSRF
Account takeover |
NA |
kishore hariram (@kishorehariram) |
Bug Bounty | 2020-04-30 | 2023-06-13 |
3483 | Weak Cryptography in Password Reset to Full Account Takeover |
Account takeover
Password reset
Cryptographic issues |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-05-15 | 2023-06-13 |
3481 | Password Reset Poisoning leading to Account Takeover |
Password reset
Account takeover |
NA |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2020-05-16 | 2023-06-13 |