2802 | Full account takeover worth $1000 Think out of the box |
Account takeover
CSRF
IDOR |
NA |
Mohsin Khan (@tabaahi_) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2794 | Story of a very lethal IDOR. |
XSS
IDOR
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-02-17 | 2023-06-13 |
2764 | IDOR which allowed me to view Personal Email Addresses of More than 50K Users! |
IDOR
Password reset |
NA |
Savir Suda (@savxiety) |
Bug Bounty | 2021-02-26 | 2023-06-13 |
2748 | Exploiting CORS to perform an IDOR Attack leading to PII Information Disclosure |
CORS misconfiguration
Information disclosure |
NA |
Harsh Parekh (@notmarshmllow) |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2719 | IDOR Vulenebility with empty response still exposing sensitive details of customers! |
IDOR |
NA |
Rahul Varale |
Bug Bounty | 2021-03-14 | 2023-06-13 |
2714 | An Interesting Account Takeover!! |
IDOR
Account takeover
Weak encryption
Password reset |
NA |
Mayank Pandey (@mayank_pandey01) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2697 | How I made it to Google HOF? |
IDOR |
Google |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2690 | How I was able to see likes and dislikes count even though is hidden by victim | YouTube #2 |
Broken Access Control
IDOR |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2021-03-26 | 2023-06-13 |
2687 | How I was able to see likes and dislikes count even though is hidden by victim | YouTube #1 |
Broken Access Control
IDOR |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2021-03-28 | 2023-06-13 |
2682 | I felt like there were no more bugs left after winning € 2000 … But an email worth €750 changed my mind |
Broken Access Control
IDOR |
NA |
Thexssrat (@theXSSrat) |
Bug Bounty | 2021-03-31 | 2023-06-13 |
2671 | Bragging Rights: Let’s head back to bug bucket |
XSS
IDOR
MFA bypass |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2637 | (POC) Update business fyi message as Facebook page analyst |
IDOR
GraphQL |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2632 | Misconfiguration in Change-password Functionality Leads to Account Takeover |
IDOR
Logic flaw
Password reset
Account takeover |
NA |
Mahmoud Radwan (@0x___2m) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2625 | IDOR leads to leaked the likes count even though is hidden by victim | YouTube ($XXXX) |
IDOR
Logic flaw |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2585 | IDOR Leads To Leak Any Uber Eats Restaurant Analytics |
IDOR |
Uber |
Prial Islam Khan (@prial261) |
Bug Bounty | 2021-05-02 | 2023-06-13 |
2571 | Workplace by Facebook | Unauthorized access to companies environment — $27,5k |
Authorization flaw
Logic flaw
IDOR |
Meta / Facebook |
Marcos Ferreira (@mvinni_) |
Bug Bounty | 2021-05-07 | 2023-06-13 |
2532 | Finding and Exploiting Unintended Functionality in Main Web App APIs |
IDOR
Information disclosure
Privilege escalation |
NA |
Bend Theory (@bendtheory) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2530 | Disclose leads form details of any Facebook Business Account or Facebook Page (Bug Bounty) |
IDOR
GraphQL |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-05-23 | 2023-06-13 |
2492 | Unexpected IDOR Vulnerability in [REDACTED] - [redacted].net (Write Up) |
IDOR |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-06-10 | 2023-06-13 |
2478 | This is how I was able to see Private, Archived Posts/Stories of users on Instagram without following them |
IDOR
GraphQL |
NA |
Mayur Fartade (@mayurfartade) |
Bug Bounty | 2021-06-15 | 2023-06-13 |
2447 | Some ways to find more IDOR |
IDOR |
NA |
Thái Vũ (@thaivd98) |
Bug Bounty | 2021-06-26 | 2023-06-13 |
2435 | Testing Cookies worth $500 |
Account takeover
IDOR |
NA |
Sankalpa Acharya (@sankalpa_02) |
Bug Bounty | 2021-06-30 | 2023-06-13 |
2433 | View Other User Private Livestream Data |
IDOR |
Meta / Facebook |
Geva (@Geva_7) |
Bug Bounty | 2021-07-03 | 2023-06-13 |
2426 | IDOR on clientauthconfig.googleapis.com |
IDOR |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-07-08 | 2023-06-13 |
2401 | Facebook Vulnerability: $1500 for Removing Document Cover |
Authorization flaw
IDOR |
Meta / Facebook |
Muhammad Sholikhin (@MuhammadLikhin) |
Bug Bounty | 2021-07-18 | 2023-06-13 |