Bugpoint – Telegram
Bugpoint
1.06K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties 📣

Rate👇
https://cutt.ly/bugpoint_rate
Feedback👇
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
IDOR on TikTok Ads Endpoint

👉 https://hackerone.com/reports/1527906

🔹 Severity: Medium | 💰 2,500 USD
🔹 Reported To: TikTok
🔹 Reported By: #sinayeganeh
🔹 State: 🟢 Resolved
🔹 Disclosed: September 1, 2022, 9:23pm (UTC)
🔥2
Wordpress users disclosure from json and xml file

👉 https://hackerone.com/reports/1408589

🔹 Severity: Low
🔹 Reported To: MTN Group
🔹 Reported By: #drak3hft7
🔹 State: 🟢 Resolved
🔹 Disclosed: September 2, 2022, 9:25am (UTC)
Weak/Auto Fill Password

👉 https://hackerone.com/reports/817331

🔹 Severity: Critical
🔹 Reported To: MTN Group
🔹 Reported By: #harrisoft
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 12:23am (UTC)
Federated share accepting/declining is not logged in audit log

👉 https://hackerone.com/reports/1200815

🔹 Severity: Low
🔹 Reported To: Nextcloud
🔹 Reported By: #rtod
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 6:12am (UTC)
Password disclosure in initial setup of Mail App

👉 https://hackerone.com/reports/1561471

🔹 Severity: Low
🔹 Reported To: Nextcloud
🔹 Reported By: #anna_larch
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 6:23am (UTC)
Brute force protections don't work

👉 https://hackerone.com/reports/1596918

🔹 Severity: Low
🔹 Reported To: Nextcloud
🔹 Reported By: #nickvergessen
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 6:25am (UTC)
Unauthenticated SSRF in 3rd party module "cerdic/csstidy"

👉 https://hackerone.com/reports/1595006

🔹 Severity: Medium | 💰 250 USD
🔹 Reported To: Nextcloud
🔹 Reported By: #eg42
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 6:29am (UTC)
path traversal vulnerability in Grafana 8.x allows " local file read "

👉 https://hackerone.com/reports/1427086

🔹 Severity: Critical
🔹 Reported To: MTN Group
🔹 Reported By: #a-heybati
🔹 State: 🟢 Resolved
🔹 Disclosed: September 3, 2022, 12:14pm (UTC)
IDOR Leads To Account Takeover Without User Interaction

👉 https://hackerone.com/reports/1272478

🔹 Severity: Critical
🔹 Reported To: MTN Group
🔹 Reported By: #theranger
🔹 State: 🟢 Resolved
🔹 Disclosed: September 4, 2022, 1:23pm (UTC)
API key (api.semrush.com) leak in JS-file

👉 https://hackerone.com/reports/1218754

🔹 Severity: Medium | 💰 500 USD
🔹 Reported To: Semrush
🔹 Reported By: #a_d_a_m
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 12:17pm (UTC)
Information disclosure through django debug mode

👉 https://hackerone.com/reports/1434276

🔹 Severity: Medium
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:56pm (UTC)
Exposed gitlab repo at https://adammanco.mtn.com/api/v4/projects

👉 https://hackerone.com/reports/1351359

🔹 Severity: Low
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:57pm (UTC)
CVE-2021-38314 @ https://www.mtn.co.rw

👉 https://hackerone.com/reports/1351341

🔹 Severity: No Rating
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:58pm (UTC)
CVE-2021-38314 @ https://www.mtn.ci

👉 https://hackerone.com/reports/1351338

🔹 Severity: Medium
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:58pm (UTC)
firebase credentials leaks @ https://mpulse.mtnonline.com

👉 https://hackerone.com/reports/1351329

🔹 Severity: Medium
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:59pm (UTC)
firebase credentials leaks @ https://mtnhottseat.mtn.com.gh

👉 https://hackerone.com/reports/1351326

🔹 Severity: Medium
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 10:59pm (UTC)
No password length restriction in reset password endpoint at http://suppliers.mtn.cm

👉 https://hackerone.com/reports/1285694

🔹 Severity: Critical
🔹 Reported To: MTN Group
🔹 Reported By: #aliyugombe
🔹 State: 🟢 Resolved
🔹 Disclosed: September 5, 2022, 11:00pm (UTC)
IDOR Payments Status

👉 https://hackerone.com/reports/1538669

🔹 Severity: Low | 💰 100 USD
🔹 Reported To: Omise
🔹 Reported By: #codeslayer137
🔹 State: 🟢 Resolved
🔹 Disclosed: September 6, 2022, 8:58am (UTC)
Modifying Sprunk vs eCola crew data

👉 https://hackerone.com/reports/1680818

🔹 Severity: Low | 💰 250 USD
🔹 Reported To: Rockstar Games
🔹 Reported By: #bugstar
🔹 State: 🟢 Resolved
🔹 Disclosed: September 6, 2022, 6:24pm (UTC)
Subdomain takeover of █████████

👉 https://hackerone.com/reports/1457928

🔹 Severity: Critical
🔹 Reported To: U.S. Dept Of Defense
🔹 Reported By: #martinvw
🔹 State: 🟢 Resolved
🔹 Disclosed: September 6, 2022, 6:50pm (UTC)
The dashboard is exposed in https://███

👉 https://hackerone.com/reports/1566758

🔹 Severity: Critical
🔹 Reported To: U.S. Dept Of Defense
🔹 Reported By: #alitoni224
🔹 State: 🟢 Resolved
🔹 Disclosed: September 6, 2022, 6:53pm (UTC)