Telegram Web
Support Portal Takeover via Leaked API KEY

๐Ÿ‘‰ https://hackerone.com/reports/1766228

๐Ÿ”น Severity: High | ๐Ÿ’ฐ 1,500 USD
๐Ÿ”น Reported To: AMBER AI
๐Ÿ”น Reported By: #khizer47
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 22, 2022, 9:55am (UTC)
DoS via Automatic Response Message

๐Ÿ‘‰ https://hackerone.com/reports/1680241

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 300 USD
๐Ÿ”น Reported To: Mattermost
๐Ÿ”น Reported By: #vultza
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 23, 2022, 2:55pm (UTC)
DoS via Playbook

๐Ÿ‘‰ https://hackerone.com/reports/1685979

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 300 USD
๐Ÿ”น Reported To: Mattermost
๐Ÿ”น Reported By: #vultza
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 23, 2022, 2:55pm (UTC)
RubyใฎCGIใƒฉใ‚คใƒ–ใƒฉใƒชใซHTTPใƒฌใ‚นใƒใƒณใ‚นๅˆ†ๅ‰ฒ๏ผˆHTTPใƒ˜ใƒƒใƒ€ใ‚คใƒณใ‚ธใ‚งใ‚ฏใ‚ทใƒงใƒณ๏ผ‰ใŒใ‚ใ‚Šใ€็ง˜ๅฏ†ๆƒ…ๅ ฑใŒๆผๆดฉใ™ใ‚‹

๐Ÿ‘‰ https://hackerone.com/reports/1204695

๐Ÿ”น Severity: High
๐Ÿ”น Reported To: Ruby
๐Ÿ”น Reported By: #htokumaru
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 24, 2022, 1:46am (UTC)
CGI::Cookieใ‚ฏใƒฉใ‚นใซใŠใ‘ใ‚‹ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃไธŠๅฅฝใพใ—ใใชใ„ไป•ๆง˜ใŠใ‚ˆใณๅฎŸ่ฃ…

๐Ÿ‘‰ https://hackerone.com/reports/1204977

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Ruby
๐Ÿ”น Reported By: #htokumaru
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 24, 2022, 1:47am (UTC)
XSS in Desktop Client in the notifications

๐Ÿ‘‰ https://hackerone.com/reports/1668028

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 750 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 11:29am (UTC)
XSS in Desktop Client via user status and information

๐Ÿ‘‰ https://hackerone.com/reports/1707977

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 3:44pm (UTC)
XSS in Desktop Client in call notification popup

๐Ÿ‘‰ https://hackerone.com/reports/1711847

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikeisastar
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 3:45pm (UTC)
SSRF - pivoting in the private LAN

๐Ÿ‘‰ https://hackerone.com/reports/1364797

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 5:20pm (UTC)
open redirect to a remote website which can phish users

๐Ÿ‘‰ https://hackerone.com/reports/1397804

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: โšช๏ธ Informative
๐Ÿ”น Disclosed: November 25, 2022, 6:08pm (UTC)
SSRF mitigation bypass using DNS Rebind attack

๐Ÿ‘‰ https://hackerone.com/reports/1369312

๐Ÿ”น Severity: Low
๐Ÿ”น Reported To: Concrete CMS
๐Ÿ”น Reported By: #adrian_t
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 25, 2022, 6:11pm (UTC)
Database resource exhaustion for logged-in users via sharee recommendations with circles

๐Ÿ‘‰ https://hackerone.com/reports/1688199

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 250 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #michag86
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 6:52am (UTC)
Profile of disabled user stays accessible

๐Ÿ‘‰ https://hackerone.com/reports/1675014

๐Ÿ”น Severity: Low | ๐Ÿ’ฐ 100 USD
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #mikaelgundersen
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 6:53am (UTC)
CVE-2022-32221: POST following PUT confusion

๐Ÿ‘‰ https://hackerone.com/reports/1704017

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: curl
๐Ÿ”น Reported By: #robbotic
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 12:02pm (UTC)
CVE-2022-42915: HTTP proxy double-free

๐Ÿ‘‰ https://hackerone.com/reports/1722065

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: curl
๐Ÿ”น Reported By: #bagder
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 12:04pm (UTC)
Exception logging in Sharepoint app reveals clear-text connection details

๐Ÿ‘‰ https://hackerone.com/reports/1652903

๐Ÿ”น Severity: Medium
๐Ÿ”น Reported To: Nextcloud
๐Ÿ”น Reported By: #kichernde_erbse
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 26, 2022, 12:46pm (UTC)
Wordpress users Disclosure [ /wp-json/wp/v2/users/ ]

๐Ÿ‘‰ https://hackerone.com/reports/1735586

๐Ÿ”น Severity: Critical
๐Ÿ”น Reported To: MTN Group
๐Ÿ”น Reported By: #shubham_srt
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 27, 2022, 3:25am (UTC)
potential denial of service attack via the locale parameter

๐Ÿ‘‰ https://hackerone.com/reports/1746098

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 2,400 USD
๐Ÿ”น Reported To: Internet Bug Bounty
๐Ÿ”น Reported By: #benjaoming_realone
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 28, 2022, 6:31pm (UTC)
I found some api keys in js files ,huge leak of token addresses and huge amount of js files are not forbidden

๐Ÿ‘‰ https://hackerone.com/reports/1787121

๐Ÿ”น Severity: No Rating
๐Ÿ”น Reported To: AMBER AI
๐Ÿ”น Reported By: #orange_h
๐Ÿ”น State: ๐Ÿ”ด N/A
๐Ÿ”น Disclosed: November 29, 2022, 10:46am (UTC)
Stored XSS in Dovetale by application of creator

๐Ÿ‘‰ https://hackerone.com/reports/1652046

๐Ÿ”น Severity: Medium | ๐Ÿ’ฐ 1,600 USD
๐Ÿ”น Reported To: Shopify
๐Ÿ”น Reported By: #kun_19
๐Ÿ”น State: ๐ŸŸข Resolved
๐Ÿ”น Disclosed: November 29, 2022, 5:34pm (UTC)
2025/02/27 16:48:11
Back to Top
HTML Embed Code: