Get Mystery Box with random crypto!

Bugpoint

Logo of telegram channel bugpoint — Bugpoint B
Logo of telegram channel bugpoint — Bugpoint
Channel address: @bugpoint
Categories: Technologies
Language: English
Subscribers: 1.23K
Description from channel

Latest updates about disclosure bug bounty reports: tech details, impacts, bounties 📣
Rate👇
https://cutt.ly/bugpoint_rate
Feedback👇
https://cutt.ly/bugpoint_feedback
#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg

Ratings & Reviews

3.00

2 reviews

Reviews can be left only by registered users. All reviews are moderated by admins.

5 stars

1

4 stars

0

3 stars

0

2 stars

0

1 stars

1


The latest Messages 7

2022-06-14 13:22:02
Reflected Cross Site Scripting at http://www.grouplogic.com/files/glidownload/verify3.asp [Uppercase Filter Bypass]

https://hackerone.com/reports/1167034

Severity: Low
Reported To: Acronis
Reported By: #ub3rsick
State: Resolved
Disclosed: June 14, 2022, 10:20am (UTC)
180 views10:22
Open / Comment
2022-06-14 06:52:02
Rails::Html::SafeListSanitizer vulnerable to xss attack in an environment that allows the style tag

https://hackerone.com/reports/1530898

Severity: Medium
Reported To: Ruby on Rails
Reported By: #windshock
State: Resolved
Disclosed: June 14, 2022, 3:49am (UTC)
200 views03:52
Open / Comment
2022-06-13 10:12:01
lack of rate limit on athentification login page & forgot password page

https://hackerone.com/reports/1591764

Severity: Medium
Reported To: Showmax
Reported By: #saidkira
State: Informative
Disclosed: June 13, 2022, 7:09am (UTC)
131 views07:12
Open / Comment
2022-06-12 02:32:02
All user password hash can be seen from admin panel

https://hackerone.com/reports/1489892

Severity: Medium
Reported To: UPchieve
Reported By: #dark_haxor
State: Resolved
Disclosed: June 11, 2022, 11:31pm (UTC)
105 views23:32
Open / Comment
2022-06-11 22:00:06
CVE-2022-30115: HSTS bypass via trailing dot

https://hackerone.com/reports/1565622

Severity: Medium | 2,400 USD
Reported To: Internet Bug Bounty
Reported By: #haxatron1
State: Resolved
Disclosed: June 11, 2022, 6:58pm (UTC)
144 views19:00
Open / Comment
2022-06-11 22:00:05
CVE-2022-27780: percent-encoded path separator in URL host

https://hackerone.com/reports/1565619

Severity: Medium | 2,400 USD
Reported To: Internet Bug Bounty
Reported By: #haxatron1
State: Resolved
Disclosed: June 11, 2022, 6:58pm (UTC)
142 views19:00
Open / Comment
2022-06-11 22:00:04
CVE-2022-27779: cookie for trailing dot TLD

https://hackerone.com/reports/1565615

Severity: Medium | 2,400 USD
Reported To: Internet Bug Bounty
Reported By: #haxatron1
State: Resolved
Disclosed: June 11, 2022, 6:58pm (UTC)
133 views19:00
Open / Comment
2022-06-11 03:36:01
disclosure the live_analytics information of any livestream.

https://hackerone.com/reports/1561299

Severity: Medium | 1,000 USD
Reported To: TikTok
Reported By: #datph4m
State: Resolved
Disclosed: June 11, 2022, 12:33am (UTC)
107 views00:36
Open / Comment
2022-06-11 03:30:02
Email address disclosure via invite token validatiion

https://hackerone.com/reports/1560072

Severity: Low | 250 USD
Reported To: TikTok
Reported By: #noob_but_cut3
State: Resolved
Disclosed: June 11, 2022, 12:28am (UTC)
107 views00:30
Open / Comment
2022-06-10 23:28:02
bd-j exploit chain

https://hackerone.com/reports/1379975

Severity: High | 20,000 USD
Reported To: PlayStation
Reported By: #theflow0
State: Resolved
Disclosed: June 10, 2022, 8:26pm (UTC)
128 views20:28
Open / Comment