3808 | Getting access to disabled/hidden features with the help of Burpsuite Match and Replace settings |
Authorization flaw |
NA |
Johns Simon (@Johnssimon22) |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3801 | Dank Writeup On Broken Access Control On An Indian Startup |
Unrestricted file upload
Authorization flaw |
NA |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2019-11-30 | 2023-06-13 |
3780 | Authorization bug that every bug hunter missed on a popular program |
Authorization flaw |
NA |
Ajinkya Pathare (@fellchase) |
Bug Bounty | 2019-12-15 | 2023-06-13 |
3753 | Bypassing Brand Collabs Manager Eligibility on Facebook |
Authorization flaw |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-12-26 | 2023-06-13 |
3720 | Adding a malicious notebook to be treated like a trusted notebook in Google Colab — 1337$ |
Authorization flaw
Logic flaw |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2020-01-17 | 2023-06-13 |
3719 | How I accidentally found Bug in Google Search Console |
Logic flaw
Authorization flaw |
Google |
Tomi (@noobe_io) |
Bug Bounty | 2020-01-18 | 2023-06-13 |
3714 | User Account Takeover via Signup Feature | Bug Bounty POC |
Account takeover
Logic flaw
Authorization flaw |
NA |
Muzammil Kayani (@muzammilabbas2) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3692 | Tumblr Bug Bounty ( $200) |
Unrestricted file upload
XSS
Authorization flaw |
Automattic |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-02 | 2023-06-13 |
3684 | Hijacking shared report links in Google Data Studio |
Authorization flaw |
Google |
sushiwushi (@sushiwushi2) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3654 | Hunting Tesla Model Y Secrets in the Parts Catalog |
Authorization flaw |
Tesla |
Evan Connelly (@Evan_Connelly) |
Bug Bounty | 2020-02-22 | 2023-06-13 |
3640 | Page Admin Disclosure via an Upgraded Page Post |
Authorization flaw
Information disclosure |
Meta / Facebook |
Dan Fabro (@0x61_) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3639 | Account Hijack using Authorization bypass $$$$ |
Account takeover
Authorization flaw |
NA |
Bhavesh Thakur (@Bhavesh_Thakur_) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3634 | SQL Injection Via Stopping the redirection to a login page |
SQL injection
Authorization flaw |
NA |
Abde Ouabala (@4mgh0z) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3575 | Restriction is not a promise : Privilege escalation on Google. |
Privilege escalation
Authorization flaw |
Google |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3541 | How was i able to find privilege escalation. |
IDOR
Authorization flaw |
NA |
Akshar Tank (@Akshar__tank) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3531 | Hiding ourself in close friend’s list and avoiding victim to remove us from his close friend’s list. |
Authorization flaw
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-04-23 | 2023-06-13 |
3530 | Messenger Rooms Bug Bounty Write-up |
Privilege escalation
Authorization flaw |
Meta / Facebook |
Jane Manchun Wong (@wongmjane) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3511 | Ok Google! bypass flag_secure’ |
Authorization flaw |
Google |
Pankaj Upadhyay (@_pupadhyay) |
Bug Bounty | 2020-05-01 | 2023-06-13 |
3506 | Private Dashboards were accessible by other Admins in Analytics Dashboard |
Authorization flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-05-02 | 2023-06-13 |
3499 | A tale of verbose error message and a JWT token |
Information disclosure
Authorization flaw |
NA |
Marek Geleta (@marek_geleta) |
Bug Bounty | 2020-05-05 | 2023-06-13 |
3466 | Easy bounties with subdomain discovery - Using Project Sonar for bug bounty |
Broken access control
Authorization flaw |
Bpost |
Torben Capiau (@TorbenCapiau) |
Bug Bounty | 2020-05-20 | 2023-06-13 |
3465 | Become member of close & public group |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-20 | 2023-06-13 |
3463 | Bypassing Message Request inbox |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3332 | Case Study I - Browser Anomaly with Facebook Apps -1500$ |
Authorization flaw |
Meta / Facebook |
easySIEM (@easySIEM) |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3320 | Global grant uri in Android 8.0-9.0 (2018 year) |
Authorization flaw |
Google |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2020-07-09 | 2023-06-13 |