Bug Bounty

HackerOne Bug Bounty Disclosure: -package-name-can-be-set-as-desired-when-submitting-a-pentest-opportunity-form-iam-srpk

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:iam_srpkLink to Submitters Profile:https://hackerone.com/iam_srpk Report Title:"package_name" can be set as desired when...

HackerOne Bug Bounty Disclosure: access-control-vulnerability-enabling-unauthorized-access-to-limited-disclosure-reports-akashhamal-x

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:akashhamal0x01Link to Submitters Profile:https://hackerone.com/akashhamal0x01 Report Title:Access Control Vulnerability Enabling Unauthorized Access to...

HackerOne Bug Bounty Disclosure: account-deletion-using-the-v-account-destroy-api-endpoint-using-account-password-without-fa-verification-erdy

Company Name: Mozilla Company HackerOne URL: https://hackerone.com/mozilla Submitted By:erdyLink to Submitters Profile:https://hackerone.com/erdy Report Title:Account deletion using the /v1/account/destroy API endpoint...

HackerOne Bug Bounty Disclosure: -spot-check-ability-to-disclose-metadata-about-spot-checks-number-of-hackers-hackers-criteria-via-spotchecksinglequery-nagli

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:nagliLink to Submitters Profile:https://hackerone.com/nagli Report Title: - Ability to disclose metadata about...

HackerOne Bug Bounty Disclosure: inadequate-redaction-exposes-sensitive-information-via-the-sharereportviaemail-graphql-endpoint-iambouali

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:iamboualiLink to Submitters Profile:https://hackerone.com/iambouali Report Title:Inadequate redaction exposes sensitive information via the...

HackerOne Bug Bounty Disclosure: changing-the-administrator-password-via-admin-console-does-not-invalidate-other-sessions-osama-hamad

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:osama-hamadLink to Submitters Profile:https://hackerone.com/osama-hamad Report Title:Changing the administrator password via...

HackerOne Bug Bounty Disclosure: a-user-with-only-modify-settings-permmision-could-takeover-any-user-accounts-osama-hamad

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:osama-hamadLink to Submitters Profile:https://hackerone.com/osama-hamad Report Title:A user with only permmision...

HackerOne Bug Bounty Disclosure: any-user-could-upload-attachments-to-pentest-scoping-form-they-don-t-have-access-to-hillybot

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:hillybot__Link to Submitters Profile:https://hackerone.com/hillybot__ Report Title:any user could upload attachments to pentest...

HackerOne Bug Bounty Disclosure: member-role-which-doesn-t-have-permission-to-send-message-can-send-by-executing-channel-commands-ramsakal

Company Name: Mattermost Company HackerOne URL: https://hackerone.com/mattermost Submitted By:ramsakal7582Link to Submitters Profile:https://hackerone.com/ramsakal7582 Report Title:Member role which doesn't have permission to...

HackerOne Bug Bounty Disclosure: a-member-with-editor-permissions-can-create-an-access-list-that-cannot-be-modified-viewed-or-deleted-mr-asg

Company Name: Teleport Company HackerOne URL: https://hackerone.com/teleport Submitted By:mr_asgLink to Submitters Profile:https://hackerone.com/mr_asg Report Title:A member with editor permissions can create...

HackerOne Bug Bounty Disclosure: improper-access-control-financial-fraud-allows-attacker-to-disclose-add-arbitrary-products-to-another-s-user-s-order-doomerhunter

Company Name: Shipt Company HackerOne URL: https://hackerone.com/shipt Submitted By:doomerhunterLink to Submitters Profile:https://hackerone.com/doomerhunter Report Title:Improper Access Control + Financial fraud allows...

HackerOne Bug Bounty Disclosure: incorrect-type-conversion-in-interpreting-ipv-mapped-ipv-addresses-and-below-curl-results-in-indeterminate-ssrf-vulnerabilities-z-r-yu

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:z3r0yuLink to Submitters Profile:https://hackerone.com/z3r0yu Report Title:Incorrect Type Conversion in interpreting IPv4-mapped IPv6...

HackerOne Bug Bounty Disclosure: insecure-direct-object-reference-protection-bypass-by-changing-http-method-in-ibm-your-learning-endpoint-suryahss

Company Name: IBM Company HackerOne URL: https://hackerone.com/ibm Submitted By:suryahssLink to Submitters Profile:https://hackerone.com/suryahss Report Title:Insecure Direct Object Reference Protection bypass by...