WakaTime: User Email Disclosure via ID-Based Invitation

The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the pri ...

Continue Reading
tulushaadi.com Cross Site Scripting vulnerability OBB-4030698

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
egmanton-pm.org.uk Cross Site Scripting vulnerability OBB-4030710

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
AWS VDP: Amazon Comprehend Medical Service Reporting “AWS Internal” for CloudTrail Events Generated from FIPS Endpoints

The Comprehend Medical service was found to have 8 API endpoints that incorrectly reported the user-agent and network information as "AWS Internal" in CloudTrail event logs. This beh ...

Continue Reading
hindishaadi.com Cross Site Scripting vulnerability OBB-4030703

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
PortSwigger Web Security: Burp Suite extensions can execute arbitrary code

Vulnerability description not...Read More ...

Continue Reading
curl: (“possible”) UAF

Vulnerability description not...Read More ...

Continue Reading
shop.stephenvilleofficepro.com Cross Site Scripting vulnerability OBB-4024515

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading

Back to Main

Subscribe for the latest news: