Month: March 2024

HackerOne Bug Bounty Disclosure: -leaking-pii-of-tour-visitors-names-email-addresses-phone-numbers-via-misconfigured-record-permissions-oxylis

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:oxylisLink to Submitters Profile:https://hackerone.com/oxylis Report Title: leaking PII of...

HackerOne Bug Bounty Disclosure: improper-authentication-login-without-registration-with-any-user-at-archyxsec

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:archyxsecLink to Submitters Profile:https://hackerone.com/archyxsec Report Title:Improper Authentication (Login without...

HackerOne Bug Bounty Disclosure: attacker-can-add-itself-as-admin-user-and-can-also-change-privileges-of-existing-users-dishant-singh

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:dishant_singhLink to Submitters Profile:https://hackerone.com/dishant_singh Report Title:Attacker can Add itself...