Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1646MSRC – Joint security research write up – Azure AD Consent bypass disclosure with Kim Jamia – Q1/2022 Authorization flaw Microsoft Joosua Santasalo (@SantasaloJoosua) Bug Bounty2022-04-092023-06-13
1583CVE-2022-25262 | JetBrains Hub single-click SAML response takeover Authorization flaw SAML OAuth JetBrains Yurii Sanin (@SaninYurii) Bug Bounty2022-05-032023-06-13
1479Same bug different platform Logic flaw Authorization flaw Meta / Facebook Prajwol Dhungana (@PrajwolDhunga14) Bug Bounty2022-06-112023-06-13
1473How I was able to see likes and dislikes count which is hidden by victim | YouTube #1 Logic flaw Authorization flaw Google Jay Jani (@JayJani007) Bug Bounty2022-06-142023-06-13
1468403 bypass on a fortune 100 financial institution (P3) Information disclosure Authorization flaw Forced browsing NA Damaidec Bug Bounty2022-06-142023-06-13
1452How I was able to see likes and dislikes count which is hidden by victim | YouTube #2 Logic flaw Authorization flaw Google Jay Jani (@JayJani007) Bug Bounty2022-06-172023-06-13
1450How I hacked one of the biggest Airline in the world IDOR Account takeover Authorization flaw NA Dali Jandro (@Sazouki_) Bug Bounty2022-06-182023-06-13
1440We were vulnerable - how a security company could have vulns Broken Access Control Authorization flaw Information disclosure Volkis Soman Verma Bug Bounty2022-06-222023-06-13
1433An Out Of Scope domain Leads To a Critical Bug[$1500] Authorization flaw Broken Access Control NA Shakti Mohanty (@3ncryptSaan) Bug Bounty2022-06-242023-06-13
1408Facebook Portal’s business logic error lead to 500$ Logic flaw Authorization flaw Meta / Facebook unurbayar amarsaikhan (@0xunuruu) Bug Bounty2022-06-302023-06-13
1346Authomize Discovers PassBleed Password Stealing and Impersonation Risks in Okta Sensitive data sent over an unencrypted channel Authorization flaw Information disclosure Okta Authomize (@Authomize) Bug Bounty2022-07-192023-06-13
1298Reading Message from Microsoft’s Private Yammer Group Authorization flaw Microsoft Meareg Bug Bounty2022-07-282023-06-13
1289How I earned $10,000 within the last 7 months — a 17y/o Edition Authorization flaw NA Gowtham Naidu Ponnana (@gowtham_ponnana) Bug Bounty2022-08-012023-06-13
1285Multiple bugs in one program leads to 1500€ Privilege escalation IDOR Authorization flaw NA can1337 (@canmustdie) Bug Bounty2022-08-022023-06-13
1173Break the Logic: 5 Different Perspectives in Single Page (€1500) Client-side enforcement of server-side security IDOR Authorization flaw NA can1337 (@canmustdie) Bug Bounty2022-08-262023-06-13
1158Exploiting Improper Validation of Amazon Simple Notification Service SigningCertUrl Authorization flaw Signature validation bypass Amazon Eugene Lim (@spaceraccoonsec) Bug Bounty2022-08-302023-06-13
1098Attackers Can Bypass GitHub Required Reviewers to Submit Malicious Code Authorization flaw Logic flaw GitHub Noam Dotan Bug Bounty2022-09-082023-06-13
1074Cloning internal Google repos for fun and… info? Authorization flaw Google Luke Berner Bug Bounty2022-09-162023-06-13
1063Privilege Escalation Leads to making authenticated actions (payment processing, creating invoices.. etc) Privilege escalation Authorization flaw NA X-Vector (@XVector11) Bug Bounty2022-09-202023-06-13
1060AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes Cloud Cross-tenant vulnerability Authorization flaw Oracle Elad Gabay (@eladgabay_) Bug Bounty2022-09-202023-06-13
988Insecure Comments IDOR Authorization flaw Microsoft Meareg Bug Bounty2022-10-072023-06-13
939Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router OS command injection Buffer Overflow Memory corruption Stored XSS Authorization flaw Information disclosure Tenda Olivier Laflamme (@olivier_boschko) Bug Bounty2022-10-192023-06-13
926Reverse Engineering the Apple Multipeer Connectivity Framework Authorization flaw Reverse engineering Networking Apple Simone Margaritelli (@evilsocket) Bug Bounty2022-10-202023-06-13
909Support supports a Hacker Social engineering Spoofing Authorization flaw Account takeover NA mechboy (@mechboy_) Bug Bounty2022-10-252023-06-13
869Invitation Hijacking Authorization flaw Privilege escalation NA vFlexo (@vflexo) Bug Bounty2022-11-032023-06-13