bug bounty

HackerOne Bug Bounty Disclosure: verification-process-done-using-different-documents-without-corresponding-to-user-information-/-user-information-can-be-changed-after-verificationbysiddharthamx

Programme HackerOne EXNESS EXNESS Submitted by siddharthamx siddharthamx Report Verification process done using different documents without corresponding to user information...

HackerOne Bug Bounty Disclosure: github-apps-can-use-scoped-user-to-server-tokens-to-obtain-full-access-to-user’s-projects-in-project-v2-graphql-apibyahacker1

Programme HackerOne GitHub GitHub Submitted by ahacker1 ahacker1 Report Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to...

HackerOne Bug Bounty Disclosure: github-security-lab-(ghsl)-vulnerability-report:-insufficient-path-validation-in-receiveexternalfilesactivity-java-(ghsl-2022-060)byatorralba

Programme HackerOne ownCloud ownCloud Submitted by atorralba atorralba Report GitHub Security Lab (GHSL) Vulnerability Report: Insufficient path validation in ReceiveExternalFilesActivity.java...

HackerOne Bug Bounty Disclosure: uninstalling-mattermost-launcher-for-windows-(64-bit),-then-reinstalling-keeps-you-logged-in-without-authenticationbyannonmous

Programme HackerOne Mattermost Mattermost Submitted by annonmous annonmous Report Uninstalling Mattermost Launcher for Windows (64-bit), then reinstalling keeps you logged...

BugCrowd Bug Bounty Disclosure: – Improper Authorization – Second (Additional) Driver can list “add-driver” invitation links – By sagarparmar121

The below information is fully automated and the information is captured from the BugCrowd Disclosure website. The information was correct...

HackerOne Bug Bounty Disclosure: csrf-vulnerability-in-nextcloud-desktop-client-3-6-1-on-windows-when-clicking-malicious-linkbylukasreschke

Programme HackerOne Nextcloud Nextcloud Submitted by lukasreschke lukasreschke Report CSRF vulnerability in Nextcloud Desktop Client 3.6.1 on Windows when clicking...