beautifulinspirationsphotography.com Cross Site Scripting vulnerability OBB-3122053

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
beautifulportraits.com Cross Site Scripting vulnerability OBB-3122054

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
bebemango.com Cross Site Scripting vulnerability OBB-3122065

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
beavertonrecruiter.com Cross Site Scripting vulnerability OBB-3122063

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
beddingandbath.com Cross Site Scripting vulnerability OBB-3122077

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
View any content private memos from other users

# Description User can view any content from private private memos from other users via api ``` PATCH /api/memo/8 HTTP/1.1 {"id":8,"rowStatus":"ARCHIVED"} ``` # Proof of Concept Login to website in b ...

Continue Reading
Archive any private memos + Delete any Shortcut + Edit any Shortcut from other users

# Description User can archive any private memos, Delete any Shortcut and Edit any Shortcut from other users via api ``` PATCH /api/memo/8 HTTP/1.1 {"id":8,"rowStatus":"ARCHIVED"} ``` ``` PATCH /api/s ...

Continue Reading
CSRF allows attacker to add malicious tags to vitim account

# Description Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a request to a Web application against which they are currently authenticated. CSRF attacks explo ...

Continue Reading

Back to Main

Subscribe for the latest news: