Month: April 2024

HackerOne Bug Bounty Disclosure: using-branded-hashtag-feature-user-partnered-with-account-manager-can-view-videos-uploaded-by-a-private-tiktok-account-if-item-id-is-known-dxcoder

Company Name: TikTok Company HackerOne URL: https://hackerone.com/tiktok Submitted By:dxcoderLink to Submitters Profile:https://hackerone.com/dxcoder Report Title:Using Branded Hashtag Feature User Partnered with...

PHPGurukul Emergency Ambulance Hiring Portal cross-site request forgery | CVE-2024-3089

NAME__________PHPGurukul Emergency Ambulance Hiring Portal cross-site request forgeryPlatforms Affected:PHPGurukul Emergency Ambulance Hiring Portal 1.0Risk Level:4.3Exploitability:HighConsequences:Gain Access DESCRIPTION__________PHPGurukul Emergency Ambulance Hiring...

PHPGurukul Emergency Ambulance Hiring Portal cross-site scripting | CVE-2024-3091

NAME__________PHPGurukul Emergency Ambulance Hiring Portal cross-site scriptingPlatforms Affected:PHPGurukul Emergency Ambulance Hiring Portal 1.0Risk Level:2.4Exploitability:HighConsequences:Cross-Site Scripting DESCRIPTION__________PHPGurukul Emergency Ambulance Hiring Portal...

PHPGurukul Emergency Ambulance Hiring Portal cross-site scripting | CVE-2024-3090

NAME__________PHPGurukul Emergency Ambulance Hiring Portal cross-site scriptingPlatforms Affected:PHPGurukul Emergency Ambulance Hiring Portal 1.0Risk Level:2.4Exploitability:HighConsequences:Cross-Site Scripting DESCRIPTION__________PHPGurukul Emergency Ambulance Hiring Portal...