2949 | Hiding from custom story privacy list is possible in FBlite making the victim unable to remove you from the list. |
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-12-24 | 2023-06-13 |
2948 | EN | Account Takeover via Web Cache Poisoning based Reflected XSS |
Reflected XSS
Web cache poisoning
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2947 | Full Address Bar Spoofing On Opera Mini Android |
Address Bar Spoofing |
Opera
Google |
Piyush Raj ~ Rex (@0x48piraj) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2946 | Facebook page admin disclosure by "Message Seller" button (Bounty: 1500 USD) |
Information disclosure |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2945 | Chaining CORS by Reflected xss to Account takeover #My first Blog |
CORS misconfiguration
Reflected XSS
Account takeover |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2944 | Regular expression injection, a code review low hanging fruit |
ReDoS |
NA |
Dominic (@dee__see) |
Bug Bounty | 2020-12-27 | 2023-06-13 |
2943 | [Google VRP] Hijacking Google Docs Screenshots |
postMessage
XSS |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2020-12-27 | 2023-06-13 |
2942 | How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete) |
CSRF |
Google |
Bhupendra Rajbhar (@bhupendra1238) |
Bug Bounty | 2020-12-28 | 2023-06-13 |
2941 | Facebook page admin disclosure by "Create doc" button (Bounty: 5000 USD) |
Information disclosure |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2020-12-28 | 2023-06-13 |
2940 | Sensitive data leak using IDOR in integration service |
IDOR |
NA |
Ronak Patel (@ronak_9889) |
Bug Bounty | 2020-12-29 | 2023-06-13 |
2939 | Cache-Key Normalization - What could go wrong? |
Web cache poisoning
DoS |
NA |
Youstin (@iustinBB) |
Bug Bounty | 2020-12-29 | 2023-06-13 |
2938 | Event Creator Is Not Able To Block The Attacker During Event Livestream |
Logic flaw |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2937 | Group Admin Can’t Able To Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020 |
Logic flaw |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2936 | Replying Comments On Someone’s Livestream From Page Is Posted As Personal Identity |
Information disclosure |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2935 | Cross Domain Referrer Leakage |
Cross-Domain Referrer Leakage |
NA |
Mohsinalibukc |
Bug Bounty | 2020-12-31 | 2023-06-13 |
2934 | Facebook bug bounty (500 USD) : A blocked fundraiser organizer would be unable to view or remove themselves from the fundraiser. |
DoS
Logic flaw |
Meta / Facebook |
Vivek ps (@vivekps143) |
Bug Bounty | 2020-12-31 | 2023-06-13 |
2932 | API based IDOR to leaking Private IP address of 6000 businesses |
IDOR |
NA |
Rafi Ahamed (Leonidas D. Ace) |
Bug Bounty | 2021-01-01 | 2023-06-13 |
2929 | Patch. Bypass. Repeat: Story of a FaceBook Page Admin Disclosure bug worth $5000 |
Information disclosure |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2021-01-04 | 2023-06-13 |
2928 | Exploiting Max. Character Limitation |
Logic flaw
DoS |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-05 | 2023-06-13 |
2927 | Privilege Escalation: From being a normal user to admin |
Privilege escalation
Broken Access Control |
NA |
Akshar Tank |
Bug Bounty | 2021-01-05 | 2023-06-13 |
2926 | Each and every request make sense… |
Privilege escalation
Exposed JWT generation endpoint
JWT |
NA |
Akshar Tank |
Bug Bounty | 2021-01-05 | 2023-06-13 |
2925 | Incident Response during Christmas |
Subdomain takeover |
NA |
TMO |
Bug Bounty | 2021-01-05 | 2023-06-13 |
2924 | Achieving Remote Code Execution By Exploiting Variable Check Feature |
RCE |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2021-01-06 | 2023-06-13 |
2923 | Nick%27s infrequently updated blog |
WAF bypass
IP spoofing |
Cloudflare |
Nick Booher |
Bug Bounty | 2021-01-06 | 2023-06-13 |
2922 | Finding bugs on Chess.com |
Lack of rate limiting
Bruteforce
CSRF |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-01-07 | 2023-06-13 |