Broken Link on Ping Identity's Vulnerability Submission Form on Hackerone
👉 https://hackerone.com/reports/1225299
🔹 Severity: Low
🔹 Reported To: Ping Identity
🔹 Reported By: #awararesearcher
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 2:23pm (UTC)
👉 https://hackerone.com/reports/1225299
🔹 Severity: Low
🔹 Reported To: Ping Identity
🔹 Reported By: #awararesearcher
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 2:23pm (UTC)
Low Privileged user can add or remove cash to/from sales register
👉 https://hackerone.com/reports/905543
🔹 Severity: Low | 💰 500 USD
🔹 Reported To: Shopify
🔹 Reported By: #sandeep_rj49
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 5:27pm (UTC)
👉 https://hackerone.com/reports/905543
🔹 Severity: Low | 💰 500 USD
🔹 Reported To: Shopify
🔹 Reported By: #sandeep_rj49
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 5:27pm (UTC)
Account Takeover on unverified emails in File Sync & Share
👉 https://hackerone.com/reports/906790
🔹 Severity: Medium | 💰 337 USD
🔹 Reported To: Acronis
🔹 Reported By: #0xcrypto
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 6:26pm (UTC)
👉 https://hackerone.com/reports/906790
🔹 Severity: Medium | 💰 337 USD
🔹 Reported To: Acronis
🔹 Reported By: #0xcrypto
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 6:26pm (UTC)
XSS on https://partners.acronis.com/
👉 https://hackerone.com/reports/979204
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #yash_
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 1:28am (UTC)
👉 https://hackerone.com/reports/979204
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #yash_
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 1:28am (UTC)
Brave Browser Tor Window leaks user's real IP to the external DNS server
👉 https://hackerone.com/reports/1077022
🔹 Severity: High | 💰 1,000 USD
🔹 Reported To: Brave Software
🔹 Reported By: #xiaoyinl
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 5:25am (UTC)
👉 https://hackerone.com/reports/1077022
🔹 Severity: High | 💰 1,000 USD
🔹 Reported To: Brave Software
🔹 Reported By: #xiaoyinl
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 5:25am (UTC)
Web cache poisoning at www.acronis.com
👉 https://hackerone.com/reports/1010858
🔹 Severity: Medium | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #9529
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 9:25am (UTC)
👉 https://hackerone.com/reports/1010858
🔹 Severity: Medium | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #9529
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 9:25am (UTC)
Malicious apps can crash Nextcloud Android client by sending malformed intents
👉 https://hackerone.com/reports/859136
🔹 Severity: No Rating
🔹 Reported To: Nextcloud
🔹 Reported By: #bigbug
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:50am (UTC)
👉 https://hackerone.com/reports/859136
🔹 Severity: No Rating
🔹 Reported To: Nextcloud
🔹 Reported By: #bigbug
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:50am (UTC)
HackerOne making payments in USDC (Coinbase stable coin)
👉 https://hackerone.com/reports/1220747
🔹 Severity: No Rating | 💰 1 USD
🔹 Reported To: HackerOne
🔹 Reported By: #arl_rose
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 2:00pm (UTC)
👉 https://hackerone.com/reports/1220747
🔹 Severity: No Rating | 💰 1 USD
🔹 Reported To: HackerOne
🔹 Reported By: #arl_rose
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 2:00pm (UTC)
TikTok Session Donation CSRF via QR code login
👉 https://hackerone.com/reports/1133661
🔹 Severity: Low | 💰 111 USD
🔹 Reported To: TikTok
🔹 Reported By: #lauritz
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 9:27pm (UTC)
👉 https://hackerone.com/reports/1133661
🔹 Severity: Low | 💰 111 USD
🔹 Reported To: TikTok
🔹 Reported By: #lauritz
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 9:27pm (UTC)
[100K-ctf] Multiple vulnerabilities leading to compromise of Pinger instance.
👉 https://hackerone.com/reports/1215867
🔹 Severity: No Rating | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #nukedx
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:27pm (UTC)
👉 https://hackerone.com/reports/1215867
🔹 Severity: No Rating | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #nukedx
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:27pm (UTC)
H1-CTF 100k Solution - Congratz on the 100k Rep todayisnew
👉 https://hackerone.com/reports/1216408
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #w31rd0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:27pm (UTC)
👉 https://hackerone.com/reports/1216408
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #w31rd0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 17, 2021, 10:27pm (UTC)
Adam and the Deadly Injections
👉 https://hackerone.com/reports/1217702
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #akshansh
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 4:58am (UTC)
👉 https://hackerone.com/reports/1217702
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #akshansh
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 4:58am (UTC)
ccc.h1ctf.com CTF
👉 https://hackerone.com/reports/1215919
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #erbbysam
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 4:59am (UTC)
👉 https://hackerone.com/reports/1215919
🔹 Severity: Critical | 💰 100 USD
🔹 Reported To: h1-ctf
🔹 Reported By: #erbbysam
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 4:59am (UTC)
Clickjacking misconfiguration bug
👉 https://hackerone.com/reports/1176104
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #niloychowdhury3
🔹 State: 🟤 Duplicate
🔹 Disclosed: June 18, 2021, 2:48pm (UTC)
👉 https://hackerone.com/reports/1176104
🔹 Severity: No Rating
🔹 Reported To: Sifchain
🔹 Reported By: #niloychowdhury3
🔹 State: 🟤 Duplicate
🔹 Disclosed: June 18, 2021, 2:48pm (UTC)
Subdomain Takeover – www.jet.acronis.com pointing to unclaimed Webflow services
👉 https://hackerone.com/reports/953719
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #sumgr0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 5:09pm (UTC)
👉 https://hackerone.com/reports/953719
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #sumgr0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 5:09pm (UTC)
Subdomain Takeover – jet.acronis.com pointing to unclaimed Webflow services
👉 https://hackerone.com/reports/952166
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #sumgr0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 5:09pm (UTC)
👉 https://hackerone.com/reports/952166
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Acronis
🔹 Reported By: #sumgr0
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 5:09pm (UTC)
Second-order SOQL injection through email and campaign name parameter in Salesforce lead submission
👉 https://hackerone.com/reports/1039821
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #jobert
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 7:15pm (UTC)
👉 https://hackerone.com/reports/1039821
🔹 Severity: Low
🔹 Reported To: HackerOne
🔹 Reported By: #jobert
🔹 State: 🟢 Resolved
🔹 Disclosed: June 18, 2021, 7:15pm (UTC)
Private ip leaking through response
👉 https://hackerone.com/reports/622937
🔹 Severity: No Rating
🔹 Reported To: Urban Company
🔹 Reported By: #t3chn0phil3
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 10:08am (UTC)
👉 https://hackerone.com/reports/622937
🔹 Severity: No Rating
🔹 Reported To: Urban Company
🔹 Reported By: #t3chn0phil3
🔹 State: 🟢 Resolved
🔹 Disclosed: June 16, 2021, 10:08am (UTC)
Broken Link on Urban Company's Vulnerability Submission Form
👉 https://hackerone.com/reports/1239334
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Urban Company
🔹 Reported By: #awararesearcher
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 9:00am (UTC)
👉 https://hackerone.com/reports/1239334
🔹 Severity: Low | 💰 50 USD
🔹 Reported To: Urban Company
🔹 Reported By: #awararesearcher
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 9:00am (UTC)
👏1
Remote Code Execution through "Files_antivirus" plugin
👉 https://hackerone.com/reports/903872
🔹 Severity: Medium
🔹 Reported To: ownCloud
🔹 Reported By: #pabl00nicarres
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 12:28pm (UTC)
👉 https://hackerone.com/reports/903872
🔹 Severity: Medium
🔹 Reported To: ownCloud
🔹 Reported By: #pabl00nicarres
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 12:28pm (UTC)
Command Injection via STARTTLS in SMTP
👉 https://hackerone.com/reports/1204962
🔹 Severity: Medium | 💰 350 USD
🔹 Reported To: Open-Xchange
🔹 Reported By: #murgi
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 1:36pm (UTC)
👉 https://hackerone.com/reports/1204962
🔹 Severity: Medium | 💰 350 USD
🔹 Reported To: Open-Xchange
🔹 Reported By: #murgi
🔹 State: 🟢 Resolved
🔹 Disclosed: June 21, 2021, 1:36pm (UTC)