3471 | Multiple flaws leads to Account Takeover within an Application |
Account takeover
Password reset |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3470 | CVE-2020–1088 — Yet another arbitrary delete EoP |
Local Privilege Escalation
Windows |
Microsoft |
Søren Fritzbøger (@fritzboger) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3468 | Teradici and CVE-2020-10965: An issue of routing. |
Missing authentication |
Teradici |
Benjamin Heald (@heald_ben) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3467 | How I got 200$ in 5 minutes – Sensitive data leak |
Information disclosure |
NA |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-19 | 2023-06-13 |
3466 | Easy bounties with subdomain discovery - Using Project Sonar for bug bounty |
Broken access control
Authorization flaw |
Bpost |
Torben Capiau (@TorbenCapiau) |
Bug Bounty | 2020-05-20 | 2023-06-13 |
3465 | Become member of close & public group |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-20 | 2023-06-13 |
3463 | Bypassing Message Request inbox |
Authorization flaw
Logic flaw |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3462 | RCE in Google Cloud Deployment Manager |
SSRF
RCE |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3461 | Parsing the DOM elements of Other pages via XSS: A Bug Bounty Story |
XSS
Information disclosure |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2020-05-22 | 2023-06-13 |
3460 | My First Bug Bounty — 2 Factor Authentication Bypass |
OTP bypass |
NA |
Talatmehmood |
Bug Bounty | 2020-05-22 | 2023-06-13 |
3459 | How Source code reading helped me find an IDOR |
IDOR
Information disclosure |
NA |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-22 | 2023-06-13 |
3458 | Story About OTP Bypass To Stored XSS |
OTP bypass
Stored XSS |
NA |
PJ Borah (@PJBorah1) |
Bug Bounty | 2020-05-23 | 2023-06-13 |
3457 | How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber |
HTTP request splitting
SSRF
CRLF injection
RCE |
Uber |
Andrey Abakumov (@andrewaeva) |
Bug Bounty | 2020-05-25 | 2023-06-13 |
3456 | Chaining an IDOR with a business-logic error to achieve critical impact |
IDOR
Logic flaw |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2020-05-26 | 2023-06-13 |
3455 | Bug Hunting Stories: Schneider Electric & The Andover Continuum Web.Client |
XXE
Reflected XSS |
Uber |
Niv Levy (@restr1ct3d) |
Bug Bounty | 2020-05-27 | 2023-06-13 |
3453 | Stored XSS in Yahoo mail IOS app($3500) |
Stored XSS |
Yahoo! / Verizon Media |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3452 | Stored XSS in Microsoft outlook |
Stored XSS |
Microsoft |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3451 | iOS Outlook Stored XSS Write-Up($3000) |
XSS |
Microsoft |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3450 | Clickjacking to Account Takeover |
Clickjacking |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3449 | A Long Overdue Write-up: How I got into the Oppo Hall of Fame |
Login screen bypass
Authentication bypass |
oppo |
Shibin B. Shaji (@shibinbshaji06) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3448 | How I was able to see Private Video Uploader Via Facebook Rights Manager.[Responsible Disclosure] |
Information disclosure |
Meta / Facebook |
Kishore TK (@kishoretk_off) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3447 | Bypassing WAF to perform XSS |
XSS |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3446 | XSS Stored On Messages In [ Outlook Web — Outlook Android App ] |
Stored XSS |
Microsoft |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3445 | Exploring macOS Calendar Alerts: Part 1 – Attempting to execute code |
Information disclosure |
Apple |
Andy Grant |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3444 | IDOR in session cookie leading to Mass Account Takeover |
IDOR
Account takeover |
NA |
Zonduhackerone (@zonduu1) |
Bug Bounty | 2020-05-29 | 2023-06-13 |