bug bounty

HackerOne Bug Bounty Disclosure: b-admin-account-panel-takeover-and-doing-actions-in-admin-panel-via-dom-based-xss-b-mouhannadlrx

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'mouhannadlrx'Link to Submitters Profile:https://hackerone.com/b'mouhannadlrx' Report Title:b'Admin account/panel takeOver and Doing actions in...

HackerOne Bug Bounty Disclosure: b-mozilla-mastodon-staging-instance-admin-api-key-disclosure-through-slack-b-griffinf

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'griffinf'Link to Submitters Profile:https://hackerone.com/b'griffinf' Report Title:b'Mozilla Mastodon Staging Instance Admin...

HackerOne Bug Bounty Disclosure: b-response-manipulation-to-enable-account-recovery-key-with-out-current-password-b-saiteja

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'saiteja1231323'Link to Submitters Profile:https://hackerone.com/b'saiteja1231323' Report Title:b'Response Manipulation to enable Account...

HackerOne Bug Bounty Disclosure: b-the-domain-is-truck-admin-eu-east-indriverapp-com-and-enter-the-management-system-of-the-blasting-mobile-phone-verification-code-b-trustworthy

Company Name: b'inDrive' Company HackerOne URL: https://hackerone.com/indrive Submitted By:b'trustworthy'Link to Submitters Profile:https://hackerone.com/b'trustworthy' Report Title:b'the domain is truck-admin.eu-east-1.indriverapp.com and Enter the...

HackerOne Bug Bounty Disclosure: b-fs-statfs-bypasses-permission-model-b-rafaelgss

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'rafaelgss'Link to Submitters Profile:https://hackerone.com/b'rafaelgss' Report Title:b'fs.statfs bypasses Permission Model'Report Link:https://hackerone.com/reports/2051224Date Submitted:10 September...

HackerOne Bug Bounty Disclosure: b-process-binding-can-bypass-the-permission-model-through-path-traversal-b-rafaelgss

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'rafaelgss'Link to Submitters Profile:https://hackerone.com/b'rafaelgss' Report Title:b'process.binding() can bypass the permission model through...

HackerOne Bug Bounty Disclosure: b-permissions-not-respected-when-copying-entire-group-folders-b-carl-schwan

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'carl_schwan'Link to Submitters Profile:https://hackerone.com/b'carl_schwan' Report Title:b'Permissions not respected when copying entire group...

HackerOne Bug Bounty Disclosure: b-support-tickets-can-be-created-on-behalf-of-other-users-using-spoofed-email-bypass-of-b-as-patro

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'as_patro'Link to Submitters Profile:https://hackerone.com/b'as_patro' Report Title:b'Support Tickets can be created on behalf...

HackerOne Bug Bounty Disclosure: b-unauthorized-ticket-can-be-created-by-an-attacker-in-user-s-helpdesk-account-b-fanimalikhack

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'fanimalikhack'Link to Submitters Profile:https://hackerone.com/b'fanimalikhack' Report Title:b"Unauthorized Ticket can be created by an...

HackerOne Bug Bounty Disclosure: b-cve-apache-airflow-spark-provider-deserialization-vulnerability-rce-b-happyhacking

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'happyhacking123'Link to Submitters Profile:https://hackerone.com/b'happyhacking123' Report Title:b'CVE-2023-40195: Apache Airflow Spark Provider...