Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3302I am able to see user’s sensitive data through JSON file. Information disclosure Authorization flaw NA Saurabh siddharam sanmane (@saurabhsanmane2) Bug Bounty2020-07-172023-06-13
3300How I lost my followers on Medium GraphQL Authorization flaw Medium Florian (@fh4ntke) Bug Bounty2020-07-172023-06-13
3285Hunting Android Application Bugs Using Android Studio. Authorization flaw Client-side enforcement of server-side security Information disclosure NA Tarek Mohammed (@Conan0x3) Bug Bounty2020-07-242023-06-13
3277CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data MacOS Local Privilege Escalation Authorization flaw Apple Matt Shockley (@mattshockl) Bug Bounty2020-07-272023-06-13
3271Authorization bypass in Google’s ticketing system (Google-GUTS) Authorization flaw Google Zohar Shachar Bug Bounty2020-07-282023-06-13
3268The Noob Way Of Taking Over Accounts Authorization flaw Account takeover Homograph attack NA Mudassir Sharief Bug Bounty2020-07-292023-06-13
3263New features means new bugs Logic flaw Authorization flaw Payment bypass NA Zseano (@zseano) Bug Bounty2020-07-302023-06-13
3205How could I Tag Photo to any user’s Scrapbook on Facebook Authorization flaw Meta / Facebook Raja Sudhakar (@Rajasudhakar) Bug Bounty2020-08-182023-06-13
3183Unhiding the hidden Client-side enforcement of server-side security Authorization flaw CSRF NA I am Broot Bug Bounty2020-08-312023-06-13
3104Weak Password Setting function on practo.com Authorization flaw Practo dark-haxor Bug Bounty2020-10-092023-06-13
3064Abusing %27Report Abuse%27 Logic flaw Authorization flaw NA Aseem Shrey (@AseemShrey) Bug Bounty2020-10-312023-06-13
3057Forcing for a bounty$$ Authorization flaw NA Rafi Ahamed (Leonidas D. Ace) Bug Bounty2020-11-032023-06-13
3055Delete Any Photos In Facebook Authorization flaw Logic flaw Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2020-11-042023-06-13
3038User’s private watched videos/saved videos exposed through a messenger call from a locked smartphone. Information disclosure Authorization flaw Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2020-11-132023-06-13
2967Disclosing the members of private Facebook Group as a non-member. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-152023-06-13
2964JavaScript analysis leading to Admin portal access Authorization flaw Broken Access Control NA Rikesh Baniya / NotRickyy (@rikeshbaniya) Bug Bounty2020-12-162023-06-13
2958Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts Information disclosure Account takeover Authorization flaw Samsung Gal Nagli (@naglinagli) Bug Bounty2020-12-182023-06-13
2911How I was able to Regain access to account deleted by Admin leading to $$$ Logic flaw Authorization flaw NA Rajesh Ranjan (@_rajesh_ranjan_) Bug Bounty2021-01-102023-06-13
2910Unauthorized Access to OData Entities + $2K Bounty From Microsoft Authorization flaw Information disclosure Microsoft Borna Nematzadeh (@LogicalHunter) Bug Bounty2021-01-102023-06-13
2883Simple & Sweet: Bypass email update restriction to change emails of team members Logic flaw Authorization flaw NA Sunil Yedla (@sunilyedla2) Bug Bounty2021-01-192023-06-13
2810How I Hacked Everyone’s Resume/CV’s and Got €€€ IDOR Authorization flaw Information disclosure NA Vishal Bharad Bug Bounty2021-02-142023-06-13
2751RocketChat - Unauthenticated access to messages Authorization flaw Rocket.Chat Rojan Rijal (@uraniumhacker) Bug Bounty2021-03-012023-06-13
2750Join Facebook Group With Unpublish Page Authorization flaw Meta / Facebook gevakun Bug Bounty2021-03-012023-06-13
2694Multiple Authorization bypass issues in Google%27s Richmedia Studio Authorization flaw Google Zohar Shachar Bug Bounty2021-03-242023-06-13
2680My first Bug report at Facebook 2021 Logic flaw Authorization flaw Meta / Facebook Kent Jarold Abulag (@wkemenhehehegsg) Bug Bounty2021-03-312023-06-13