bug bounty

HackerOne Bug Bounty Disclosure: b-reflected-xss-in-oauth-complete-endpoints-b-zerodivisi-n

Company Name: b'Mattermost' Company HackerOne URL: https://hackerone.com/mattermost Submitted By:b'zerodivisi0n'Link to Submitters Profile:https://hackerone.com/b'zerodivisi0n' Report Title:b'Reflected XSS in OAuth complete endpoints'Report Link:https://hackerone.com/reports/1502099Date...

HackerOne Bug Bounty Disclosure: b-missing-function-level-access-control-in-mozilla-formula-containsregular-expression-denial-of-service-cve-b-unexpectedbuffercon

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'unexpectedbuffercon_'Link to Submitters Profile:https://hackerone.com/b'unexpectedbuffercon_' Report Title:b'Missing Function Level Access Control...

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-mozaws-net-b-mikey

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'mikey96'Link to Submitters Profile:https://hackerone.com/b'mikey96' Report Title:b'Subdomain Takeover on mozaws.net'Report Link:https://hackerone.com/reports/2171494Date...

HackerOne Bug Bounty Disclosure: b-existance-of-calendars-and-addressbooks-can-be-checked-by-unauthenticated-users-b-themarkib-x

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'themarkib0x0'Link to Submitters Profile:https://hackerone.com/b'themarkib0x0' Report Title:b'Existance of calendars and addressbooks can be...

HackerOne Bug Bounty Disclosure: b-no-rate-limit-on-forgot-password-on-https-apps-nextcloud-com-b-cyber-world

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'cyber_world_01'Link to Submitters Profile:https://hackerone.com/b'cyber_world_01' Report Title:b'No Rate Limit On Forgot Password on...

HackerOne Bug Bounty Disclosure: b-dos-in-form-submission-at-https-nextcloud-com-instant-trial-b-krrish-hackk

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'krrish_hackk'Link to Submitters Profile:https://hackerone.com/b'krrish_hackk' Report Title:b'Dos in Form Submission at https://nextcloud.com/instant-trial/'Report Link:https://hackerone.com/reports/1901396Date...

HackerOne Bug Bounty Disclosure: b-nextcloud-all-in-one-path-disclosure-of-internal-frontend-b-shuvam

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'shuvam321'Link to Submitters Profile:https://hackerone.com/b'shuvam321' Report Title:b'Nextcloud All-In-One path disclosure of internal frontend'Report...

HackerOne Bug Bounty Disclosure: b-email-verification-bypass-for-manual-connection-setup-service-credentials-b-yozzo

Company Name: b'Nord Security' Company HackerOne URL: https://hackerone.com/nordsecurity Submitted By:b'yozzo_'Link to Submitters Profile:https://hackerone.com/b'yozzo_' Report Title:b'Email verification bypass for manual connection...

HackerOne Bug Bounty Disclosure: b-aws-keys-and-user-cookie-leakage-via-uninitialized-memory-leak-in-outdated-librsvg-version-in-basecamp-b-neex

Company Name: b'Basecamp' Company HackerOne URL: https://hackerone.com/basecamp Submitted By:b'neex'Link to Submitters Profile:https://hackerone.com/b'neex' Report Title:b'AWS keys and user cookie leakage via...

HackerOne Bug Bounty Disclosure: b-stored-xss-on-bugzilla-mozilla-org-via-comment-edit-feature-from-non-admin-to-admin-b-r-dpars-c

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'r3dpars3c'Link to Submitters Profile:https://hackerone.com/b'r3dpars3c' Report Title:b'Stored Xss on bugzilla.mozilla.org via...

HackerOne Bug Bounty Disclosure: b-if-rate-limit-is-hit-ip-address-is-leaked-to-anyone-who-tries-to-login-b-anish-kosaraju

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'anish_kosaraju'Link to Submitters Profile:https://hackerone.com/b'anish_kosaraju' Report Title:b'If rate limit is hit,...

HackerOne Bug Bounty Disclosure: b-permanent-casb-integration-takeover-due-to-improper-access-controls-confused-deputy-problem-b-suzuka

Company Name: b'Cloudflare Public Bug Bounty' Company HackerOne URL: https://hackerone.com/cloudflare Submitted By:b'suzuka'Link to Submitters Profile:https://hackerone.com/b'suzuka' Report Title:b'Permanent CASB Integration Takeover...

HackerOne Bug Bounty Disclosure: b-unprotected-atlantis-server-at-https-b-imranhudaa

Company Name: b'8x8' Company HackerOne URL: https://hackerone.com/8x8 Submitted By:b'imranhudaa'Link to Submitters Profile:https://hackerone.com/b'imranhudaa' Report Title:b'Unprotected Atlantis Server at https://132.226..'Report Link:https://hackerone.com/reports/1895783Date Submitted:15...

HackerOne Bug Bounty Disclosure: b-able-to-see-bonus-amount-given-to-a-report-even-if-the-bounty-and-bonus-is-not-visible-to-public-or-mentioned-in-report-id-json-b-callmed

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'callmed0_4'Link to Submitters Profile:https://hackerone.com/b'callmed0_4' Report Title:b'Able to see Bonus amount given to...

HackerOne Bug Bounty Disclosure: b-multiple-cross-site-scripting-xss-vulnerabilities-in-revive-adserver-b-l-stb-t

Company Name: b'Revive Adserver' Company HackerOne URL: https://hackerone.com/revive_adserver Submitted By:b'l4stb1t'Link to Submitters Profile:https://hackerone.com/b'l4stb1t' Report Title:b'Multiple cross-site scripting (XSS) vulnerabilities in...

HackerOne Bug Bounty Disclosure: b-idor-authorization-bypass-in-lockreport-mutation-for-public-reports-b-verw-tch

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'0verw4tch'Link to Submitters Profile:https://hackerone.com/b'0verw4tch' Report Title:b'IDOR: Authorization Bypass in LockReport Mutation for...

HackerOne Bug Bounty Disclosure: b-information-disclosure-pvt-gitlab-issue-disclosing-through-gitlab-unfiltered-youtube-channel-b-mrrajputhacker

Company Name: b'GitLab' Company HackerOne URL: https://hackerone.com/gitlab Submitted By:b'mrrajputhacker2'Link to Submitters Profile:https://hackerone.com/b'mrrajputhacker2' Report Title:b'Information Disclosure - Pvt Gitlab Issue Disclosing...

HackerOne Bug Bounty Disclosure: b-request-english-versions-of-web-pages-for-enhanced-privacy-keeps-previous-grayed-out-settings-b-andreien

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'andreien'Link to Submitters Profile:https://hackerone.com/b'andreien' Report Title:b"'Request English versions of web pages for...