Support Portal Takeover via Leaked API KEY
๐ https://hackerone.com/reports/1766228
๐น Severity: High | ๐ฐ 1,500 USD
๐น Reported To: AMBER AI
๐น Reported By: #khizer47
๐น State: ๐ข Resolved
๐น Disclosed: November 22, 2022, 9:55am (UTC)
๐ https://hackerone.com/reports/1766228
๐น Severity: High | ๐ฐ 1,500 USD
๐น Reported To: AMBER AI
๐น Reported By: #khizer47
๐น State: ๐ข Resolved
๐น Disclosed: November 22, 2022, 9:55am (UTC)
DoS via Automatic Response Message
๐ https://hackerone.com/reports/1680241
๐น Severity: Medium | ๐ฐ 300 USD
๐น Reported To: Mattermost
๐น Reported By: #vultza
๐น State: ๐ข Resolved
๐น Disclosed: November 23, 2022, 2:55pm (UTC)
๐ https://hackerone.com/reports/1680241
๐น Severity: Medium | ๐ฐ 300 USD
๐น Reported To: Mattermost
๐น Reported By: #vultza
๐น State: ๐ข Resolved
๐น Disclosed: November 23, 2022, 2:55pm (UTC)
DoS via Playbook
๐ https://hackerone.com/reports/1685979
๐น Severity: Medium | ๐ฐ 300 USD
๐น Reported To: Mattermost
๐น Reported By: #vultza
๐น State: ๐ข Resolved
๐น Disclosed: November 23, 2022, 2:55pm (UTC)
๐ https://hackerone.com/reports/1685979
๐น Severity: Medium | ๐ฐ 300 USD
๐น Reported To: Mattermost
๐น Reported By: #vultza
๐น State: ๐ข Resolved
๐น Disclosed: November 23, 2022, 2:55pm (UTC)
RubyใฎCGIใฉใคใใฉใชใซHTTPใฌในใใณในๅๅฒ๏ผHTTPใใใใคใณใธใงใฏใทใงใณ๏ผใใใใ็งๅฏๆ
ๅ ฑใๆผๆดฉใใ
๐ https://hackerone.com/reports/1204695
๐น Severity: High
๐น Reported To: Ruby
๐น Reported By: #htokumaru
๐น State: ๐ข Resolved
๐น Disclosed: November 24, 2022, 1:46am (UTC)
๐ https://hackerone.com/reports/1204695
๐น Severity: High
๐น Reported To: Ruby
๐น Reported By: #htokumaru
๐น State: ๐ข Resolved
๐น Disclosed: November 24, 2022, 1:46am (UTC)
CGI::Cookieใฏใฉในใซใใใใปใญใฅใชใใฃไธๅฅฝใพใใใชใไปๆงใใใณๅฎ่ฃ
๐ https://hackerone.com/reports/1204977
๐น Severity: Low
๐น Reported To: Ruby
๐น Reported By: #htokumaru
๐น State: ๐ข Resolved
๐น Disclosed: November 24, 2022, 1:47am (UTC)
๐ https://hackerone.com/reports/1204977
๐น Severity: Low
๐น Reported To: Ruby
๐น Reported By: #htokumaru
๐น State: ๐ข Resolved
๐น Disclosed: November 24, 2022, 1:47am (UTC)
XSS in Desktop Client in the notifications
๐ https://hackerone.com/reports/1668028
๐น Severity: Low | ๐ฐ 750 USD
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 11:29am (UTC)
๐ https://hackerone.com/reports/1668028
๐น Severity: Low | ๐ฐ 750 USD
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 11:29am (UTC)
XSS in Desktop Client via user status and information
๐ https://hackerone.com/reports/1707977
๐น Severity: Low
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 3:44pm (UTC)
๐ https://hackerone.com/reports/1707977
๐น Severity: Low
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 3:44pm (UTC)
XSS in Desktop Client in call notification popup
๐ https://hackerone.com/reports/1711847
๐น Severity: Low
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 3:45pm (UTC)
๐ https://hackerone.com/reports/1711847
๐น Severity: Low
๐น Reported To: Nextcloud
๐น Reported By: #mikeisastar
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 3:45pm (UTC)
SSRF - pivoting in the private LAN
๐ https://hackerone.com/reports/1364797
๐น Severity: Low
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 5:20pm (UTC)
๐ https://hackerone.com/reports/1364797
๐น Severity: Low
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 5:20pm (UTC)
open redirect to a remote website which can phish users
๐ https://hackerone.com/reports/1397804
๐น Severity: Medium
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: โช๏ธ Informative
๐น Disclosed: November 25, 2022, 6:08pm (UTC)
๐ https://hackerone.com/reports/1397804
๐น Severity: Medium
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: โช๏ธ Informative
๐น Disclosed: November 25, 2022, 6:08pm (UTC)
SSRF mitigation bypass using DNS Rebind attack
๐ https://hackerone.com/reports/1369312
๐น Severity: Low
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 6:11pm (UTC)
๐ https://hackerone.com/reports/1369312
๐น Severity: Low
๐น Reported To: Concrete CMS
๐น Reported By: #adrian_t
๐น State: ๐ข Resolved
๐น Disclosed: November 25, 2022, 6:11pm (UTC)
Database resource exhaustion for logged-in users via sharee recommendations with circles
๐ https://hackerone.com/reports/1688199
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Nextcloud
๐น Reported By: #michag86
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 6:52am (UTC)
๐ https://hackerone.com/reports/1688199
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Nextcloud
๐น Reported By: #michag86
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 6:52am (UTC)
Profile of disabled user stays accessible
๐ https://hackerone.com/reports/1675014
๐น Severity: Low | ๐ฐ 100 USD
๐น Reported To: Nextcloud
๐น Reported By: #mikaelgundersen
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 6:53am (UTC)
๐ https://hackerone.com/reports/1675014
๐น Severity: Low | ๐ฐ 100 USD
๐น Reported To: Nextcloud
๐น Reported By: #mikaelgundersen
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 6:53am (UTC)
CVE-2022-32221: POST following PUT confusion
๐ https://hackerone.com/reports/1704017
๐น Severity: Medium
๐น Reported To: curl
๐น Reported By: #robbotic
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:02pm (UTC)
๐ https://hackerone.com/reports/1704017
๐น Severity: Medium
๐น Reported To: curl
๐น Reported By: #robbotic
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:02pm (UTC)
CVE-2022-42915: HTTP proxy double-free
๐ https://hackerone.com/reports/1722065
๐น Severity: Medium
๐น Reported To: curl
๐น Reported By: #bagder
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:04pm (UTC)
๐ https://hackerone.com/reports/1722065
๐น Severity: Medium
๐น Reported To: curl
๐น Reported By: #bagder
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:04pm (UTC)
Exception logging in Sharepoint app reveals clear-text connection details
๐ https://hackerone.com/reports/1652903
๐น Severity: Medium
๐น Reported To: Nextcloud
๐น Reported By: #kichernde_erbse
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:46pm (UTC)
๐ https://hackerone.com/reports/1652903
๐น Severity: Medium
๐น Reported To: Nextcloud
๐น Reported By: #kichernde_erbse
๐น State: ๐ข Resolved
๐น Disclosed: November 26, 2022, 12:46pm (UTC)
Wordpress users Disclosure [ /wp-json/wp/v2/users/ ]
๐ https://hackerone.com/reports/1735586
๐น Severity: Critical
๐น Reported To: MTN Group
๐น Reported By: #shubham_srt
๐น State: ๐ข Resolved
๐น Disclosed: November 27, 2022, 3:25am (UTC)
๐ https://hackerone.com/reports/1735586
๐น Severity: Critical
๐น Reported To: MTN Group
๐น Reported By: #shubham_srt
๐น State: ๐ข Resolved
๐น Disclosed: November 27, 2022, 3:25am (UTC)
potential denial of service attack via the locale parameter
๐ https://hackerone.com/reports/1746098
๐น Severity: Medium | ๐ฐ 2,400 USD
๐น Reported To: Internet Bug Bounty
๐น Reported By: #benjaoming_realone
๐น State: ๐ข Resolved
๐น Disclosed: November 28, 2022, 6:31pm (UTC)
๐ https://hackerone.com/reports/1746098
๐น Severity: Medium | ๐ฐ 2,400 USD
๐น Reported To: Internet Bug Bounty
๐น Reported By: #benjaoming_realone
๐น State: ๐ข Resolved
๐น Disclosed: November 28, 2022, 6:31pm (UTC)
I found some api keys in js files ,huge leak of token addresses and huge amount of js files are not forbidden
๐ https://hackerone.com/reports/1787121
๐น Severity: No Rating
๐น Reported To: AMBER AI
๐น Reported By: #orange_h
๐น State: ๐ด N/A
๐น Disclosed: November 29, 2022, 10:46am (UTC)
๐ https://hackerone.com/reports/1787121
๐น Severity: No Rating
๐น Reported To: AMBER AI
๐น Reported By: #orange_h
๐น State: ๐ด N/A
๐น Disclosed: November 29, 2022, 10:46am (UTC)
Stored XSS in Dovetale by application of creator
๐ https://hackerone.com/reports/1652046
๐น Severity: Medium | ๐ฐ 1,600 USD
๐น Reported To: Shopify
๐น Reported By: #kun_19
๐น State: ๐ข Resolved
๐น Disclosed: November 29, 2022, 5:34pm (UTC)
๐ https://hackerone.com/reports/1652046
๐น Severity: Medium | ๐ฐ 1,600 USD
๐น Reported To: Shopify
๐น Reported By: #kun_19
๐น State: ๐ข Resolved
๐น Disclosed: November 29, 2022, 5:34pm (UTC)