WakaTime: User Email Disclosure via ID-Based Invitation

The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the pri ...

Continue Reading
seedparade.co.uk Improper Access Control vulnerability OBB-4027566

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
sendabienesraices.com Improper Access Control vulnerability OBB-4027564

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
britcham.org.sg Open Redirect vulnerability OBB-4027452

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
serres-et-abris.com Improper Access Control vulnerability OBB-4027565

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
yoshimura-jp.com Cross Site Scripting vulnerability OBB-4030585

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
AWS VDP: Amazon Comprehend Medical Service Reporting “AWS Internal” for CloudTrail Events Generated from FIPS Endpoints

The Comprehend Medical service was found to have 8 API endpoints that incorrectly reported the user-agent and network information as "AWS Internal" in CloudTrail event logs. This beh ...

Continue Reading
XVIDEOS: API Data Leakage Vulnerability Report – `xvcams.com`

Vulnerability description not...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: