3480 | Chained Bugs [ Account TakeOver ] |
IDOR
XSS
Account takeover |
NA |
Bilal Khan (@bilalmerokhel) |
Bug Bounty | 2020-05-16 | 2023-06-13 |
3477 | One Param => $10k |
IDOR
XSS
Account takeover |
NA |
Bilal Khan (@bilalmerokhel) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3475 | Tale of Account Takeovers (Part-2) |
Account takeover |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3471 | Multiple flaws leads to Account Takeover within an Application |
Account takeover
Password reset |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3450 | Clickjacking to Account Takeover |
Clickjacking |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3444 | IDOR in session cookie leading to Mass Account Takeover |
IDOR
Account takeover |
NA |
Zonduhackerone (@zonduu1) |
Bug Bounty | 2020-05-29 | 2023-06-13 |
3439 | Zero-day in Sign in with Apple |
Account takeover |
Apple |
Bhavuk Jain (@bhavukjain1) |
Bug Bounty | 2020-05-30 | 2023-06-13 |
3426 | From CRLF to Account Takeover |
CRLF injection
HTTP response splitting
Reflected XSS
Account takeover |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-06-03 | 2023-06-13 |
3418 | Account takeover via postMessage |
Account takeover
postMessage |
NA |
socket (@yxw21) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3406 | Utilizing Lockdown: Blind Sqli leads to Account Takeover & Data Extraction |
Blind SQL injection
Account takeover |
NA |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3398 | Account Takeover via OTP Bruteforce (Apigee API) |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2020-06-13 | 2023-06-13 |
3391 | Another "Fappening" on the Horizon? |
Account takeover
Phishing |
Apple |
Sociosploit |
Bug Bounty | 2020-06-15 | 2023-06-13 |
3390 | Business logic flaw in the invitation system allows to Takeover any account at a private company |
Account takeover
IDOR |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2020-06-15 | 2023-06-13 |
3364 | How i hacked worldwide ZOOM users |
OAuth
Account takeover |
Zoom |
s3c (@s3c_krd) |
Bug Bounty | 2020-06-27 | 2023-06-13 |
3360 | How I was able to take over any account via the Password Reset Functionality. |
Password reset
Account takeover |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3358 | Taking over Azure DevOps Accounts with 1 Click |
Subdomain takeover
Account takeover |
Microsoft |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3357 | API Endpoint leads to Account Takeover In Android Application |
Exposed token generation endpoint
Information disclosure |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3338 | EN | Account Takeover and Sensitive Data Leakage via CORS Misconfiguration |
CORS misconfiguration
CSRF
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-07-04 | 2023-06-13 |
3313 | A tale of critical account take over |
Account takeover
Exposed JWT generation endpoint
JWT |
NA |
Shivam Pandey (@shivam31200) |
Bug Bounty | 2020-07-10 | 2023-06-13 |
3309 | Self stored xss to full account takeover |
XSS
Account takeover |
NA |
Jatin Aesthetic (@techyfreakk) |
Bug Bounty | 2020-07-12 | 2023-06-13 |
3304 | Admin ,Editor can disclose personnel email of other editor, admin on page(who created shop) |
Information disclosure |
Meta / Facebook |
The 3 Day Account Takeover |
Bug Bounty | 2020-07-16 | 2023-06-13 |
3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3284 | A $5000 Account Takeover |
Account takeover
Password reset |
NA |
neelam |
Bug Bounty | 2020-07-25 | 2023-06-13 |
3276 | CSRF + Open Redirect To Account Takeover |
CSRF
Open redirect
Account takeover |
NA |
R29k (@R29k_) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3274 | Pre-Access to Victim’s Account via Facebook Signup |
OAuth
Account takeover |
NA |
Akshansh Jaiswal (@Akshanshjaiswl) |
Bug Bounty | 2020-07-28 | 2023-06-13 |