SSRF at jira.plazius.ru - CVE-2019-8451
👉 https://hackerone.com/reports/900618
🔹 Severity: High | 💰 1,200 USD
🔹 Reported To: Mail.ru
🔹 Reported By: #cutedoggo
🔹 State: 🟢 Resolved
🔹 Disclosed: May 12, 2021, 3:48pm (UTC)
👉 https://hackerone.com/reports/900618
🔹 Severity: High | 💰 1,200 USD
🔹 Reported To: Mail.ru
🔹 Reported By: #cutedoggo
🔹 State: 🟢 Resolved
🔹 Disclosed: May 12, 2021, 3:48pm (UTC)
Social media links not working
👉 https://hackerone.com/reports/1189282
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #tefa_
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 12, 2021, 5:41pm (UTC)
👉 https://hackerone.com/reports/1189282
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #tefa_
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 12, 2021, 5:41pm (UTC)
CORS Misconfiguration
👉 https://hackerone.com/reports/1194280
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #itsme_ani
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 12, 2021, 6:01pm (UTC)
👉 https://hackerone.com/reports/1194280
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #itsme_ani
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 12, 2021, 6:01pm (UTC)
Wordpress Users Disclosure (/wp-json/wp/v2/users/) on sifchain.finance
👉 https://hackerone.com/reports/1195194
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #ibrahimauwal1
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 12:43am (UTC)
👉 https://hackerone.com/reports/1195194
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #ibrahimauwal1
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 12:43am (UTC)
Cross Origin Resource Sharing Misconfiguration | Lead to sensitive information.
👉 https://hackerone.com/reports/1189363
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #immortalsurya
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 3:32am (UTC)
👉 https://hackerone.com/reports/1189363
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #immortalsurya
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 3:32am (UTC)
CSRF allows to test email forwarding
👉 https://hackerone.com/reports/1131473
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #muon4
🔹 State: 🟢 Resolved
🔹 Disclosed: May 13, 2021, 5:22am (UTC)
👉 https://hackerone.com/reports/1131473
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #muon4
🔹 State: 🟢 Resolved
🔹 Disclosed: May 13, 2021, 5:22am (UTC)
Lack warning label when receiving a letter
👉 https://hackerone.com/reports/1128701
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #haxta4ok00
🔹 State: 🟢 Resolved
🔹 Disclosed: May 13, 2021, 8:25am (UTC)
👉 https://hackerone.com/reports/1128701
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #haxta4ok00
🔹 State: 🟢 Resolved
🔹 Disclosed: May 13, 2021, 8:25am (UTC)
Email spoofing
👉 https://hackerone.com/reports/1187511
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #tmsm
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 10:20am (UTC)
👉 https://hackerone.com/reports/1187511
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #tmsm
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 13, 2021, 10:20am (UTC)
Path Transversal inside saveContracts.js
👉 https://hackerone.com/reports/1196917
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #caon
🔹 State: 🔴 N/A
🔹 Disclosed: May 14, 2021, 12:47am (UTC)
👉 https://hackerone.com/reports/1196917
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #caon
🔹 State: 🔴 N/A
🔹 Disclosed: May 14, 2021, 12:47am (UTC)
Found a url on source code which was disclosing different juicy informations like ip addresses and available endponts
👉 https://hackerone.com/reports/1195432
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #paranoid07
🔹 State: 🔴 N/A
🔹 Disclosed: May 14, 2021, 3:25pm (UTC)
👉 https://hackerone.com/reports/1195432
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #paranoid07
🔹 State: 🔴 N/A
🔹 Disclosed: May 14, 2021, 3:25pm (UTC)
No Rate Limit protection in user subnoscription form
👉 https://hackerone.com/reports/1195429
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #aliyugombe
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 4:58pm (UTC)
👉 https://hackerone.com/reports/1195429
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #aliyugombe
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 4:58pm (UTC)
Corss-Tenant IDOR on Business allowing escalation privilege, invitation takeover, and edition of any other Businesses' employees
👉 https://hackerone.com/reports/1063022
🔹 Severity: Medium | 💰 1,250 USD
🔹 Reported To: Uber
🔹 Reported By: #bubbounty
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:02pm (UTC)
👉 https://hackerone.com/reports/1063022
🔹 Severity: Medium | 💰 1,250 USD
🔹 Reported To: Uber
🔹 Reported By: #bubbounty
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:02pm (UTC)
Unrestricted File Upload Results in Cross-Site Scripting Attacks
👉 https://hackerone.com/reports/1005355
🔹 Severity: Medium | 💰 2,000 USD
🔹 Reported To: Uber
🔹 Reported By: #hunt4p1zza
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:04pm (UTC)
👉 https://hackerone.com/reports/1005355
🔹 Severity: Medium | 💰 2,000 USD
🔹 Reported To: Uber
🔹 Reported By: #hunt4p1zza
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:04pm (UTC)
No Valid SPF Records/don't have DMARC record
👉 https://hackerone.com/reports/1194598
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #himan253
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 5:19pm (UTC)
👉 https://hackerone.com/reports/1194598
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #himan253
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 5:19pm (UTC)
Request Access for Uber Device Returns Management Platform (https://www.eats-devicereturns.com/request-access/) Bypass Allows Access to PII
👉 https://hackerone.com/reports/1010787
🔹 Severity: High | 💰 750 USD
🔹 Reported To: Uber
🔹 Reported By: #hunt4p1zza
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:24pm (UTC)
👉 https://hackerone.com/reports/1010787
🔹 Severity: High | 💰 750 USD
🔹 Reported To: Uber
🔹 Reported By: #hunt4p1zza
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:24pm (UTC)
Subdomain takeover of ████.jitsi.net
👉 https://hackerone.com/reports/1197013
🔹 Severity: High
🔹 Reported To: 8x8
🔹 Reported By: #ian
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:35pm (UTC)
👉 https://hackerone.com/reports/1197013
🔹 Severity: High
🔹 Reported To: 8x8
🔹 Reported By: #ian
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 5:35pm (UTC)
RCE when removing metadata with ExifTool
👉 https://hackerone.com/reports/1154542
🔹 Severity: Critical | 💰 20,000 USD
🔹 Reported To: GitLab
🔹 Reported By: #vakzz
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 8:08pm (UTC)
👉 https://hackerone.com/reports/1154542
🔹 Severity: Critical | 💰 20,000 USD
🔹 Reported To: GitLab
🔹 Reported By: #vakzz
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 8:08pm (UTC)
Full account takeover of any user through reset password
👉 https://hackerone.com/reports/1175081
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #saajanbhujel
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 9:28pm (UTC)
👉 https://hackerone.com/reports/1175081
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #saajanbhujel
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 14, 2021, 9:28pm (UTC)
Zero click account Takeover due to Api misconfiguration 🏂🎩
👉 https://hackerone.com/reports/1166500
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #zero_or_1
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 9:36pm (UTC)
👉 https://hackerone.com/reports/1166500
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #zero_or_1
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 9:36pm (UTC)
private passenger information is exposed to the Uber Driver app during ride dispatch ("Ping") events
👉 https://hackerone.com/reports/174404
🔹 Severity: Medium | 💰 750 USD
🔹 Reported To: Uber
🔹 Reported By: #beezlewaxin
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 10:35pm (UTC)
👉 https://hackerone.com/reports/174404
🔹 Severity: Medium | 💰 750 USD
🔹 Reported To: Uber
🔹 Reported By: #beezlewaxin
🔹 State: 🟢 Resolved
🔹 Disclosed: May 14, 2021, 10:35pm (UTC)
Information Disclosure on https://rpc.sifchain.finance/
👉 https://hackerone.com/reports/1197035
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #bringing2021
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 15, 2021, 4:04am (UTC)
👉 https://hackerone.com/reports/1197035
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #bringing2021
🔹 State: 🟤 Duplicate
🔹 Disclosed: May 15, 2021, 4:04am (UTC)