3465 | Become member of close & public group |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-20 | 2023-06-13 |
3463 | Bypassing Message Request inbox |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3456 | Chaining an IDOR with a business-logic error to achieve critical impact |
IDOR
Logic flaw |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2020-05-26 | 2023-06-13 |
3437 | The story of My First $xxx Bug Bounty From Facebook |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2020-05-31 | 2023-06-13 |
3390 | Business logic flaw in the invitation system allows to Takeover any account at a private company |
Account takeover
IDOR |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2020-06-15 | 2023-06-13 |
3366 | Bug Bounty in Lockdown (SQLi and Business Logic) |
SQL injection
Logic flaw |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-06-24 | 2023-06-13 |
3365 | Create hidden comment by blocking an Admin: Facebook Bug Bounty 2020 |
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-06-25 | 2023-06-13 |
3344 | Price Tampering due to Improper checks on applying Coupon |
Payment tampering
Logic flaw |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3342 | Breaking Business Logic via Coupons — The Story of my 1st Valid Bug Bounty |
Payment tampering
Logic flaw |
NA |
Dominic Ifediri (@Edi4all) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3319 | Exploiting Application Logic to Referral Code Disclosure |
Logic flaw
Information disclosure |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3301 | The Story of My first 4 digit bounty from Facebook |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3294 | bypass user-restriction registration |
Logic flaw
Payment tampering |
NA |
Mohamed Ayad |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3289 | Increasing reward points N number of time |
Logic flaw |
NA |
Saddam Hussain (@wisdomfreak1) |
Bug Bounty | 2020-07-21 | 2023-06-13 |
3265 | Exploiting Business Logic — Wallet Money |
Payment tampering
Logic flaw |
NA |
Keshav Malik (@g0t_rOoT_) |
Bug Bounty | 2020-07-30 | 2023-06-13 |
3264 | Weird Behavior of Facebook Page FAQ Leading to Bounty from Facebook |
Logic flaw |
Meta / Facebook |
Ashok Chapagai (@ashokcpg) |
Bug Bounty | 2020-07-30 | 2023-06-13 |
3263 | New features means new bugs |
Logic flaw
Authorization flaw
Payment bypass |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-07-30 | 2023-06-13 |
3260 | Unauthd - Logic bugs FTW |
Logic flaw |
Apple |
Ilias Morad (@A2nkF_) |
Bug Bounty | 2020-07-31 | 2023-06-13 |
3259 | CVE-2020–9854: "Unauthd" - (three) logic bugs ftw! |
Local Privilege Escalation
Logic flaw |
Apple |
Ilias Morad (@A2nkF_) |
Bug Bounty | 2020-08-01 | 2023-06-13 |
3252 | Account takeover in cups.mail.ru |
Logic flaw
Password reset
Account takeover |
Mail.ru |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-08-03 | 2023-06-13 |
3248 | I want all these features |
Logic flaw
Payment tampering |
NA |
Mohamed Ayad |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3247 | CSRF PoC mistake that broke crucial functions for the end user/victim |
Logic flaw |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3236 | Bypassing Google Maps API Key Restrictions |
Logic flaw |
Google |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3233 | My 2nd 4digit Bug Bounty From Facebook |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2020-08-10 | 2023-06-13 |
3230 | Group Admin Can’t Able to Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020 |
Logic flaw |
Meta / Facebook |
Prakash Panta (@Prakashpanta268) |
Bug Bounty | 2020-08-11 | 2023-06-13 |