2973 | Exploiting new-era of Request forgery on mobile applications |
CSRF
Account takeover |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2965 | TikTok Careers Portal Account Takeover |
CSRF
Open redirect
Account takeover |
TikTok |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2020-12-15 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2942 | How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete) |
CSRF |
Google |
Bhupendra Rajbhar (@bhupendra1238) |
Bug Bounty | 2020-12-28 | 2023-06-13 |
2922 | Finding bugs on Chess.com |
Lack of rate limiting
Bruteforce
CSRF |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2904 | CSRF with IDOR - A Deadly Combo |
CSRF
IDOR |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2875 | CSRF Protection Bypass in Atlassian Confluence Server |
CSRF |
Atlassian |
yeuchimse (@yeuchimse) |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2855 | Launching Internal & Non-Exported Deeplinks On Facebook |
CSRF |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2842 | Stealing Chat session ID with CORS and execute CSRF attack |
CSRF
CORS misconfiguration |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2814 | OAuth Misconfiguration Leads to Full Account takeover |
OAuth
Clickjacking
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-13 | 2023-06-13 |
2802 | Full account takeover worth $1000 Think out of the box |
Account takeover
CSRF
IDOR |
NA |
Mohsin Khan (@tabaahi_) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2780 | CSRF In JSF 2.0: Predicting CSRF Tokens For Apache MyFaces |
CSRF
ViewState |
Apache |
Wolfgang Ettlinger |
Bug Bounty | 2021-02-19 | 2023-06-13 |
2771 | CSRF through URL with # tag parameter |
CSRF |
NA |
Tommysuriel |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2708 | Chaining bugs for the greater good |
Blind XSS
CSRF |
NA |
mohamad mahmoudi (@Lotus_619) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2684 | CSRF to Full Account Takeover |
CSRF
Account takeover |
NA |
Ashraf Harb (@ashrafharb97) |
Bug Bounty | 2021-03-29 | 2023-06-13 |
2681 | Missing CORS leads to Complete Account Takeover |
Missing CORS
CSRF
Account takeover |
NA |
Niraj Modi (@nirajmodi51) |
Bug Bounty | 2021-03-30 | 2023-06-13 |
2662 | CSRF in YouTube Leanback API |
CSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2657 | I Built a TV That Plays All of Your Private YouTube Videos |
CSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2616 | Got Nice catch by Google |
OAuth
Open redirect
CSRF |
Google |
Parth Desani (@DesaniParth) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2587 | Chaining CSRF with XSS to deactivate Mass user accounts by single click |
CSRF
XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-02 | 2023-06-13 |
2583 | Deep Dive into Open Source Bug Bounty |
CSRF |
NA |
Ritik Sahni (@ritiksahni22) |
Bug Bounty | 2021-05-03 | 2023-06-13 |
2534 | CSRF from which we can create a support ticket in Victim’s Account (500$) |
CSRF |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2533 | Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$) |
Information disclosure |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2501 | Executing CSRF With Phone Validation |
CSRF |
NA |
Greg Gibson |
Bug Bounty | 2021-06-04 | 2023-06-13 |
2473 | Part-1 Dive into Zoom Applications |
CSRF
Payment bypass
Logic flaw
Account takeover
Privilege escalation |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-06-16 | 2023-06-13 |