2451 | A supply-chain breach: Taking over an Atlassian account |
XSS
CSRF |
Atlassian |
Dikla Barda, Yaara Shriki |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2415 | Part 2: Dive into Zoom Applications |
CSRF
Account takeover
Information disclosure
Session expiration issue
Authorization flaw
Logic flaw |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2380 | You’ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures |
Password reset
Host header injection
CSRF
Account takeover |
NA |
Tommaso Innocenti (@innotommy) |
Bug Bounty | 2021-07-26 | 2023-06-13 |
2353 | how to be popular |
CSRF
Type confusion |
OkCupid |
yan (@bcrypt) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2335 | Multiple Vulnerabilities In cPanel/WHM |
XXE
Stored XSS
Privilege escalation
CSRF
Cross-Site WebSocket Hijacking (CSWH) |
cPanel |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2021-08-10 | 2023-06-13 |
2321 | Why u should use burp to test Path Traversal Vulnerability and also get RXSS |
Path traversal
XSS
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2310 | How I found my first Subdomain Takeover vulnerability |
Subdomain takeover
CSRF |
NA |
Monish Basaniwal |
Bug Bounty | 2021-08-20 | 2023-06-13 |
2264 | chaining bugs from self XSS to account takeover |
Self-XSS
WAF bypass
CSRF
Account takeover |
NA |
Behnam Yazdanpanah (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2247 | 2 CSRF 1 IDOR on Google Marketing Platform |
IDOR
CSRF |
Google |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2167 | CSRF to one tray Red-bull |
CSRF |
Redbull |
Mohammed Saneem |
Bug Bounty | 2021-10-06 | 2023-06-13 |
2145 | Exploitation of file’s download parameters to create potential risk of malware delivery: $200 bug! |
CSRF
RCE |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2138 | Exploiting Request forgery on Mobile Applications. |
CSRF
Account takeover
Android
iOS |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2085 | chaining improper authentication to idor and no rate limit for mass account takeover |
Account takeover
Lack of rate limiting
CSRF
IDOR |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2073 | Diving into Open-source LMS Codebases |
Insecure file upload
Insecure deserialization
RCE
CSRF
SQL injection
Reflected XSS |
Moodle
Chamilo LMS |
Poh Jia Hao (@Chocologicall) |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2063 | Exploiting OAuth: Journey to Account Takeover |
Account takeover
OAuth
XSS
Weak CSP
CSRF |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2030 | AWS SageMaker Jupyter Notebook Instance Takeover |
Self-XSS
CSRF
RCE |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
1963 | Story of a weird CSRF bug |
CSRF |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-29 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1924 | Pwning the portal: from database dump to session hijacking |
SQL injection
XSS
CSRF |
NA |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-01-12 | 2023-06-13 |
1911 | Stealing administrative JWT%27s through post auth SSRF (CVE-2021-22056) |
SSRF
CSRF |
VMware |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1859 | Abusing Facebooks `Call To Action` To Launch Internal Deeplinks |
CSRF
Android
iOS |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1857 | A technique to semi-automatically find vulnerabilities in WordPress plugins |
XSS
SQL injection
Open redirect
CSRF |
NA |
kazet (@kazet1234) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1839 | CVE-2022-21703: cross-origin request forgery against Grafana |
CSRF
SSRF |
Grafana Labs |
Julien Cretel (@jub0bs) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1794 | What an injection into jQuery-selector can lead to |
CSRF |
NA |
Anton Subbotin (@ska_vans) |
Bug Bounty | 2022-02-21 | 2023-06-13 |
1696 | Bug Bounty Adventures: A NodeBB 0-day |
CSRF
Account takeover
SSO
Authentication flaw |
Opera |
Marouane Mouhtadi (@Mar0_0uane) |
Bug Bounty | 2022-03-25 | 2023-06-13 |