Forwarded from HackerOne (Amir Kiani)
https://news.1rj.ru/str/bugpoint
Good Channel for Public Bug Bounty Write-Up
Good Channel for Public Bug Bounty Write-Up
Telegram
Bugpoint
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties 📣
Rate👇
https://cutt.ly/bugpoint_rate
Feedback👇
https://cutt.ly/bugpoint_feedback
#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Rate👇
https://cutt.ly/bugpoint_rate
Feedback👇
https://cutt.ly/bugpoint_feedback
#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
IDOR — Sensitive Data Exposure (IOS Application)
https://helmay.medium.com/bug-bounty-idor-sensitive-data-exposure-ios-application-ba80c93887a9
https://helmay.medium.com/bug-bounty-idor-sensitive-data-exposure-ios-application-ba80c93887a9
Medium
[BUG BOUNTY] IDOR — Sensitive Data Exposure (IOS Application)
بسم الله الرحمن الرحيم
Post-Auth Stored XSS with User Interaction leads to Remote Code Execution
https://hackerone.com/reports/1132202
https://hackerone.com/reports/1132202
HackerOne
Rocket.Chat disclosed on HackerOne: Post-Auth Stored XSS with User...
**Summary:**
Unsafe usage of the `toastr` library leads to Stored XSS when combined with a validation bypass in the `createRoom` function. Targeting an admin account leads to Remote Code...
Unsafe usage of the `toastr` library leads to Stored XSS when combined with a validation bypass in the `createRoom` function. Targeting an admin account leads to Remote Code...
Remote code execution in cdnjs of Cloudflare
https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/
https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/
blog.ryotak.net
Remote code execution in cdnjs of Cloudflare
Preface
(日本語版も公開されています。)
Cloudflare, which runs cdnjs, is running a “Vulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments.
This article describes vulnerabilities reported through this program and published…
(日本語版も公開されています。)
Cloudflare, which runs cdnjs, is running a “Vulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments.
This article describes vulnerabilities reported through this program and published…
Privilege Escalation vulnerability in steam's Remote Play feature leads to arbitrary kernel-mode driver installation
https://hackerone.com/reports/852091
https://hackerone.com/reports/852091
HackerOne
Valve disclosed on HackerOne: Privilege Escalation vulnerability in...
_Tested on Windows 10 x64_
* On Steam starting, it will check all installed files' Integrity, and re-download the modified file(s). This step makes every single file in Steam installation folder...
* On Steam starting, it will check all installed files' Integrity, and re-download the modified file(s). This step makes every single file in Steam installation folder...