Bug Bounty

HackerOne Bug Bounty Disclosure: a-potential-risk-in-the-cloudfrontextensionsconsole-which-can-be-used-to-privilege-escalation-zolaer

Company Name: AWS VDP Company HackerOne URL: https://hackerone.com/aws_vdp Submitted By:zolaer9527Link to Submitters Profile:https://hackerone.com/zolaer9527 Report Title:A potential risk in the cloudFrontExtensionsConsole...

HackerOne Bug Bounty Disclosure: hackerone-supports-accounts-organitation-takeover-madara

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:madara_Link to Submitters Profile:https://hackerone.com/madara_ Report Title:Hackerone supports accounts organitation takeoverReport Link:https://hackerone.com/reports/2798380Date Submitted:19...

HackerOne Bug Bounty Disclosure: heap-buffer-overread-in-contains-whitespace-when-calling-parser-validate-after-supplying-a-maliciously-crafted-buffer-to-parser-parse-l-thaxor

Company Name: Cosmos Company HackerOne URL: https://hackerone.com/cosmos Submitted By:l33thaxorLink to Submitters Profile:https://hackerone.com/l33thaxor Report Title:Heap-Buffer-Overread in contains_whitespace when calling parser_validate after...

HackerOne Bug Bounty Disclosure: unauthenticated-phpinfo-files-could-lead-to-ability-file-read-at-h-f-n-ips-mtn-co-ug-offensiveops

Company Name: MTN Group Company HackerOne URL: https://hackerone.com/mtn_group Submitted By:offensiveopsLink to Submitters Profile:https://hackerone.com/offensiveops Report Title:Unauthenticated phpinfo()files could lead to ability...

HackerOne Bug Bounty Disclosure: mail-auto-configurator-can-be-tricked-into-sending-account-information-to-wrong-servers-shushangw

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:shushangwLink to Submitters Profile:https://hackerone.com/shushangw Report Title:Mail auto configurator can be tricked into...

HackerOne Bug Bounty Disclosure: attachments-folder-for-text-app-is-accessible-on-files-drop-password-protected-shares-lukasreschke

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:lukasreschkeLink to Submitters Profile:https://hackerone.com/lukasreschke Report Title:Attachments folder for Text app is accessible...

HackerOne Bug Bounty Disclosure: availability-impact-from-exploiting-project-name-vulnerabilities-mr-root

Company Name: Doppler Company HackerOne URL: https://hackerone.com/doppler Submitted By:mr_root_0101Link to Submitters Profile:https://hackerone.com/mr_root_0101 Report Title:Availability Impact from Exploiting Project Name VulnerabilitiesReport...

HackerOne Bug Bounty Disclosure: exploitable-format-string-vulnerability-in-curl-mfprintf-function-reterix

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:reterixLink to Submitters Profile:https://hackerone.com/reterix Report Title:Exploitable Format String Vulnerability in curl_mfprintf FunctionReport...

HackerOne Bug Bounty Disclosure: open-redirect-via-redirect-to-parameter-in-tumblr-com-shivangmauryaa

Company Name: Automattic Company HackerOne URL: https://hackerone.com/automattic Submitted By:shivangmauryaaLink to Submitters Profile:https://hackerone.com/shivangmauryaa Report Title:Open redirect via redirect_to parameter in tumblrcomReport...