readme.md

January 20, 2023 · View on GitHub

Title

SSRF in Exchange leads to ROOT access in all instances

URL

https://hackerone.com/reports/341876

Severity score

6.9

Reporter

0xacb

Bounty paid

$25,000


Title

SSRF на https://target.my.com/

URL

https://hackerone.com/reports/200224

Severity score

5.4

Reporter

0x01alka

Bounty paid

$800


Title

SSRF in Export template to ActiveCampaign

URL

https://hackerone.com/reports/754025

Severity score

null

Reporter

c1kada

Bounty paid

null


Title

Server Side Request Forgery (SSRF) vulnerability in a DoD website

URL

https://hackerone.com/reports/189648

Severity score

null

Reporter

korprit

Bounty paid

null


Title

Server Side Request Forgery on JSON Feed

URL

https://hackerone.com/reports/280511

Severity score

null

Reporter

mr_r3boot

Bounty paid

null


Title

SSRF and local file disclosure by video upload on https://www.redtube.com/upload

URL

https://hackerone.com/reports/570537

Severity score

null

Reporter

tony_tsep

Bounty paid

$500


Title

TURN server allows TCP and UDP proxying to internal network, localhost and meta-data services

URL

https://hackerone.com/reports/333419

Severity score

null

Reporter

sandrogauci

Bounty paid

$3,500


Title

GitLab's GitHub integration is vulnerable to SSRF vulnerability

URL

https://hackerone.com/reports/446593

Severity score

null

Reporter

jobert

Bounty paid

$2,000


Title

SSRF - RSS feed, blacklist bypass (IP Formatting)

URL

https://hackerone.com/reports/299130

Severity score

null

Reporter

logan5

Bounty paid

$850


Title

Attacker can send requests from mail.ru server

URL

https://hackerone.com/reports/347850

Severity score

null

Reporter

aieti

Bounty paid

$800


Title

SSRF in https://cards-dev.twitter.com/validator

URL

https://hackerone.com/reports/178184

Severity score

null

Reporter

mindaugas

Bounty paid

$280


Title

SSRF via webhook

URL

https://hackerone.com/reports/243277

Severity score

null

Reporter

cablej

Bounty paid

null


Title

SSRF in ███████

URL

https://hackerone.com/reports/207477

Severity score

null

Reporter

akaki

Bounty paid

null


Title

[et.mail.ru] ssrf 2

URL

https://hackerone.com/reports/258237

Severity score

null

Reporter

haxta4ok00

Bounty paid

$150


Title

[out-of-scope] toxiproxy: Lack of CSRF protection allows an attacker to gain access to internal Shopify network

URL

https://hackerone.com/reports/236349

Severity score

null

Reporter

bored-engineer

Bounty paid

null


Title

SSRF in Search.gov via ?url= parameter

URL

https://hackerone.com/reports/514224

Severity score

3.8

Reporter

niwasaki

Bounty paid

$150


Title

Potensial SSRF via Git repository URL

URL

https://hackerone.com/reports/359288

Severity score

null

Reporter

rootbakar___

Bounty paid

null


Title

ssrf xspa [https://prt.mail.ru/] 2

URL

https://hackerone.com/reports/216533

Severity score

null

Reporter

haxta4ok00

Bounty paid

$150


Title

SSRF via git Repo by URL Abuse

URL

https://hackerone.com/reports/191216

Severity score

6.6

Reporter

pwnisher

Bounty paid

null


Title

Blind SSRF in emblem editor (2)

URL

https://hackerone.com/reports/265050

Severity score

null

Reporter

alexbirsan

Bounty paid

$1,500


Title

CRLF injection & SSRF in git:// protocal lead to arbitrary code execution

URL

https://hackerone.com/reports/441090

Severity score

8.5

Reporter

chromium1337

Bounty paid

null


Title

Additional bypass allows SSRF for internal netblocks

URL

https://hackerone.com/reports/288950

Severity score

null

Reporter

edoverflow

Bounty paid

null


Title

Half-Blind SSRF found in kube/cloud-controller-manager can be upgraded to complete SSRF (fully crafted HTTP requests) in vendor managed k8s service.

URL

https://hackerone.com/reports/776017

Severity score

8.8

Reporter

reeverzax

Bounty paid

$5,000


Title

[h1-2006 2020] Bounty payments are done !

URL

https://hackerone.com/reports/895824

Severity score

null

Reporter

louzogh

Bounty paid

null


Title

Open redirect bypass & SSRF Security Vulnerability

URL

https://hackerone.com/reports/771465

Severity score

null

Reporter

snwlol

Bounty paid

null


Title

Blind SSRF/XSPA on dashboard.lob.com + blind code injection

URL

https://hackerone.com/reports/517461

Severity score

null

Reporter

ninjajuju

Bounty paid

null


Title

Blind SSRF in /appsuite/api/oxodocumentfilter&action=addfile

URL

https://hackerone.com/reports/865652

Severity score

5

Reporter

skr0x1c0

Bounty paid

$550


Title

SSRF thru File Replace

URL

https://hackerone.com/reports/243865

Severity score

null

Reporter

zuh4n

Bounty paid

null


Title

SSRF and local file disclosure by video upload on https://www.tube8.com/

URL

https://hackerone.com/reports/574133

Severity score

null

Reporter

tony_tsep

Bounty paid

$500


Title

SSRF Possible through /wordpress/xmlrpc.php

URL

https://hackerone.com/reports/1004847

Severity score

0

Reporter

azzassin

Bounty paid

null


Title

Server-Side Request Forgery in "icons.bitwarden.net"

URL

https://hackerone.com/reports/913276

Severity score

null

Reporter

njgadhiya

Bounty paid

null


Title

SSRF leaking internal google cloud data through upload function [SSH Keys, etc..]

URL

https://hackerone.com/reports/549882

Severity score

9

Reporter

dphoeniixx

Bounty paid

$5,000


Title

[SSRF] PDF documentconverterws

URL

https://hackerone.com/reports/361793

Severity score

null

Reporter

secator

Bounty paid

$850


Title

SSRF & LFR on city-mobil.ru

URL

https://hackerone.com/reports/748128

Severity score

8.3

Reporter

byq

Bounty paid

$6,000


Title

SSRF in CI after first run

URL

https://hackerone.com/reports/369451

Severity score

null

Reporter

plazmaz

Bounty paid

$3,000


Title

[H1-2006 2020] CTF Writeup

URL

https://hackerone.com/reports/893305

Severity score

null

Reporter

leoastorga_g

Bounty paid

null


Title

[Limited bypass of #793704] Blind SSRF in Ghost CMS

URL

https://hackerone.com/reports/815084

Severity score

2.7

Reporter

ryotak

Bounty paid

null


Title

cURL / libcURL - CVE-2016-8624 invalid URL parsing with '#'

URL

https://hackerone.com/reports/180434

Severity score

6.5

Reporter

fms

Bounty paid

$500


Title

[H1-415 2020] CTF Writeup

URL

https://hackerone.com/reports/776634

Severity score

null

Reporter

manoelt

Bounty paid

$500


Title

Blind SSRF on http://info.ucs.ru/settings/check/

URL

https://hackerone.com/reports/901050

Severity score

4.4

Reporter

elmahdi

Bounty paid

$250


Title

Potential SSRF in sales.mail.ru

URL

https://hackerone.com/reports/97395

Severity score

5.9

Reporter

paresh_parmar

Bounty paid

$300


Title

Bypass for blind SSRF #281950 and #287496

URL

https://hackerone.com/reports/642675

Severity score

null

Reporter

7001

Bounty paid

null


Title

SSRF in webhooks leads to AWS private keys disclosure

URL

https://hackerone.com/reports/508459

Severity score

7.1

Reporter

honoki

Bounty paid

$700


Title

SSRF in alerts.newrelic.com exposes entire internal network

URL

https://hackerone.com/reports/198690

Severity score

null

Reporter

albinowax

Bounty paid

null


Title

[qiwi.me] No limits on image download requests

URL

https://hackerone.com/reports/227806

Severity score

null

Reporter

circuit

Bounty paid

$100


Title

Blind SSRF due to img tag injection in career form

URL

https://hackerone.com/reports/236301

Severity score

null

Reporter

encrypt

Bounty paid

null


Title

https://████████ Impacted by DNN ImageHandler SSRF

URL

https://hackerone.com/reports/482634

Severity score

null

Reporter

warsong

Bounty paid

null


Title

Server Side Request Forgery in 'Jabber settings' in Admin Control Panel

URL

https://hackerone.com/reports/1018568

Severity score

3.4

Reporter

they

Bounty paid

null


Title

Internal SSRF bypass using slash commands at api.slack.com

URL

https://hackerone.com/reports/356765

Severity score

null

Reporter

albatraoz

Bounty paid

$500


Title

SSRF in api.slack.com, using slash commands and bypassing the protections.

URL

https://hackerone.com/reports/381129

Severity score

null

Reporter

elber

Bounty paid

$500


Title

SSRF leads to internal port scan

URL

https://hackerone.com/reports/764517

Severity score

null

Reporter

theoriginal

Bounty paid

null


Title

Blind SSRF in magnum upgrade_params

URL

https://hackerone.com/reports/907819

Severity score

null

Reporter

paul_axe

Bounty paid

$2,500


Title

Blind SSRF in horizon-heat

URL

https://hackerone.com/reports/893856

Severity score

null

Reporter

paul_axe

Bounty paid

$2,500


Title

Blind SSRF at https://chaturbate.com/notifications/update_push/

URL

https://hackerone.com/reports/411865

Severity score

null

Reporter

robin0oklay

Bounty paid

$1,250


Title

SSRF on music.line.me through getXML.php

URL

https://hackerone.com/reports/746024

Severity score

null

Reporter

hahwul

Bounty paid

$4,500


Title

Full Read SSRF on Gitlab's Internal Grafana

URL

https://hackerone.com/reports/878779

Severity score

null

Reporter

rhynorater

Bounty paid

$12,000


Title

[h1-2006 2020] CTF Walkthrough

URL

https://hackerone.com/reports/895780

Severity score

null

Reporter

meraxes

Bounty paid

null


Title

Unsecured Kibana/Elasticsearch instance

URL

https://hackerone.com/reports/188482

Severity score

null

Reporter

cyber-guard

Bounty paid

$750


Title

Internal Ports Scanning via Blind SSRF (URL Redirection to beat filter)

URL

https://hackerone.com/reports/287496

Severity score

null

Reporter

spicyturtle

Bounty paid

null


Title

SSRF in https://www.zomato.com████ allows reading local files and website source code

URL

https://hackerone.com/reports/271224

Severity score

9.8

Reporter

adibou

Bounty paid

$1,000


Title

SSRF on fleet.city-mobil.ru leads to local file read

URL

https://hackerone.com/reports/748069

Severity score

6.7

Reporter

byq

Bounty paid

$6,000


Title

SSRF in /cabinet/stripeapi/v1/siteInfoLookup?url=XXX

URL

https://hackerone.com/reports/738553

Severity score

5.3

Reporter

eliel

Bounty paid

null


Title

SSRF - Office Documents - Image URL

URL

https://hackerone.com/reports/738015

Severity score

null

Reporter

zhutyra

Bounty paid

$450


Title

Inappropriate URL parsing may cause security risk!

URL

https://hackerone.com/reports/305974

Severity score

null

Reporter

orange

Bounty paid

$1,000


Title

SSRF - Guard - Unchecked WKS servers

URL

https://hackerone.com/reports/792960

Severity score

5

Reporter

zhutyra

Bounty paid

$400


Title

SSRF at ideas.starbucks.com

URL

https://hackerone.com/reports/500468

Severity score

7.9

Reporter

damian89

Bounty paid

$1,000


Title

Server Side Request Forgery (SSRF) at app.hellosign.com leads to AWS private keys disclosure

URL

https://hackerone.com/reports/923132

Severity score

null

Reporter

sayaanalam

Bounty paid

$4,913


Title

SSRF in /appsuite/api/autoconfig

URL

https://hackerone.com/reports/293847

Severity score

null

Reporter

logan5

Bounty paid

$850


Title

SSRF via Export Service in ActiveCampaign

URL

https://hackerone.com/reports/847101

Severity score

null

Reporter

dotsecurity

Bounty paid

null


Title

SSRF on local storage of iOS mobile

URL

https://hackerone.com/reports/746541

Severity score

null

Reporter

l0l1ch3ng

Bounty paid

null


Title

Blind SSRF in ads.tiktok.com

URL

https://hackerone.com/reports/1006599

Severity score

3.7

Reporter

chihuahua

Bounty paid

$150


Title

SSRF in proxy.duckduckgo.com via the image_host parameter

URL

https://hackerone.com/reports/358119

Severity score

7.5

Reporter

fpatrik

Bounty paid

null


Title

XSPA on API service endpoint

URL

https://hackerone.com/reports/751625

Severity score

null

Reporter

kunal94

Bounty paid

null


Title

SSRF at apps.nextcloud.com/developer/apps/releases/new

URL

https://hackerone.com/reports/213358

Severity score

null

Reporter

t-pwn

Bounty paid

null


Title

WebLogic Server Side Request Forgery

URL

https://hackerone.com/reports/300513

Severity score

null

Reporter

linkks

Bounty paid

null


Title

[h1-415 2020] Chain of vulnerabilities leading to account takeover and unauthorized access of sensitive internal resources

URL

https://hackerone.com/reports/781281

Severity score

9

Reporter

checkm50

Bounty paid

null


Title

Reverse Proxy misroute leading to steal X-Shopify-Access-Token header

URL

https://hackerone.com/reports/429617

Severity score

null

Reporter

chaosbolt

Bounty paid

$1,000


Title

Server-Side request forgery in New-Subscription feature of the calendar app

URL

https://hackerone.com/reports/427835

Severity score

5

Reporter

foobar7

Bounty paid

$100


Title

SSRF vulnerability in gitlab.com via project import.

URL

https://hackerone.com/reports/215105

Severity score

5.4

Reporter

edoverflow

Bounty paid

null


Title

SSRF and local file disclosure by video upload on http://www.youporn.com/

URL

https://hackerone.com/reports/574134

Severity score

null

Reporter

tony_tsep

Bounty paid

$500


Title

SSRF in hatchful.shopify.com

URL

https://hackerone.com/reports/409701

Severity score

null

Reporter

zhurig

Bounty paid

$500


Title

SSRF - Image Sources in HTML Snippets - 727234 bypass

URL

https://hackerone.com/reports/737163

Severity score

null

Reporter

zhutyra

Bounty paid

$400


Title

SSRF via 3d.cs.money/pasteLinkToImage

URL

https://hackerone.com/reports/832858

Severity score

5.2

Reporter

putsi

Bounty paid

$250


Title

GitLab::UrlBlocker validation bypass leading to full Server Side Request Forgery

URL

https://hackerone.com/reports/541169

Severity score

7.6

Reporter

ajxchapman

Bounty paid

$5,000


Title

SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE

URL

https://hackerone.com/reports/288353

Severity score

null

Reporter

alexbirsan

Bounty paid

$1,500


Title

Bypass of the SSRF protection in Event Subscriptions parameter.

URL

https://hackerone.com/reports/386292

Severity score

null

Reporter

elber

Bounty paid

$500


Title

SSRF on ████████

URL

https://hackerone.com/reports/406387

Severity score

null

Reporter

twicedi

Bounty paid

null


Title

SVG Server Side Request Forgery (SSRF)

URL

https://hackerone.com/reports/223203

Severity score

null

Reporter

floyd

Bounty paid

$500


Title

Limited code execution vulnerability on a DoD website

URL

https://hackerone.com/reports/229199

Severity score

null

Reporter

sp1d3rs

Bounty paid

null


Title

Server side request forgery

URL

https://hackerone.com/reports/427227

Severity score

4

Reporter

linkks

Bounty paid

$300


Title

Blind SSRF in "Integrations" by abusing a bug in Ruby's native resolver.

URL

https://hackerone.com/reports/287245

Severity score

null

Reporter

edoverflow

Bounty paid

null


Title

[H1-2006 2020] CTF write-up

URL

https://hackerone.com/reports/890555

Severity score

null

Reporter

counterbreach

Bounty paid

null


Title

SSRF into Shared Runner, by replacing dockerd with malicious server in Executor

URL

https://hackerone.com/reports/809248

Severity score

null

Reporter

lucash-dev

Bounty paid

$2,000


Title

SSRF/XSPA in labs.data.gov/dashboard/validate

URL

https://hackerone.com/reports/272095

Severity score

4.6

Reporter

haxta4ok00

Bounty paid

$300


Title

xmlrpc.php file enabled

URL

https://hackerone.com/reports/773888

Severity score

null

Reporter

p4nk4jv

Bounty paid

null


Title

Grafana SSRF in grafana.instamart.ru

URL

https://hackerone.com/reports/895551

Severity score

6.7

Reporter

buggi3

Bounty paid

$1,200


Title

SSRF in clients.city-mobil.ru

URL

https://hackerone.com/reports/712103

Severity score

8.5

Reporter

johndoe1492

Bounty paid

$1,500


Title

SSRF - Blacklist bypass for mail account addition

URL

https://hackerone.com/reports/303378

Severity score

null

Reporter

logan5

Bounty paid

$500


Title

Blind HTTP GET SSRF via website icon fetch (bypass of pull#812)

URL

https://hackerone.com/reports/925527

Severity score

null

Reporter

shielder

Bounty paid

null


Title

Injection of http.<url>.* git config settings leading to SSRF

URL

https://hackerone.com/reports/855276

Severity score

null

Reporter

vakzz

Bounty paid

$3,000


Title

SSRF In plantuml (on plantuml.pre.gitlab.com)

URL

https://hackerone.com/reports/689245

Severity score

null

Reporter

plazmaz

Bounty paid

$100


Title

Blind SSRF while Creating Templates

URL

https://hackerone.com/reports/800909

Severity score

null

Reporter

dotsecurity

Bounty paid

null


Title

SSRF vulnerability on ██████████ leaks internal IP and various sensitive information

URL

https://hackerone.com/reports/310036

Severity score

null

Reporter

alyssa_herrera

Bounty paid

null


Title

SSRF and LFI in site-audit tool

URL

https://hackerone.com/reports/794099

Severity score

null

Reporter

a_d_a_m

Bounty paid

$2,000


Title

Upload profile photo from URL

URL

https://hackerone.com/reports/713

Severity score

null

Reporter

zurke

Bounty paid

$500


Title

SSRF In Get Video Contents

URL

https://hackerone.com/reports/643622

Severity score

null

Reporter

artemis233

Bounty paid

$500


Title

Server-Side Request Forgery (SSRF)

URL

https://hackerone.com/reports/382048

Severity score

null

Reporter

t-pwn

Bounty paid

null


Title

[Uppy] Internal Server side request forgery (bypass of #786956)

URL

https://hackerone.com/reports/891270

Severity score

9.3

Reporter

mahmoud0x00

Bounty paid

null


Title

[H1-2006 2020] CTF Writeup

URL

https://hackerone.com/reports/887766

Severity score

null

Reporter

0xcaptainfreak

Bounty paid

null


Title

Blind SSRF at https://chat.makerdao.com/account/profile

URL

https://hackerone.com/reports/846184

Severity score

9.8

Reporter

losthacker

Bounty paid

null


Title

SSRF - Guard - Unchecked HKP servers

URL

https://hackerone.com/reports/792953

Severity score

5

Reporter

zhutyra

Bounty paid

$400


Title

SSRF in imgur video GIF conversion

URL

https://hackerone.com/reports/247680

Severity score

null

Reporter

mariuszpoplawski

Bounty paid

$1,000


Title

SSRF on █████████ Allowing internal server data access

URL

https://hackerone.com/reports/326040

Severity score

null

Reporter

alyssa_herrera

Bounty paid

null


Title

Unauthenticated blind SSRF in OAuth Jira authorization controller

URL

https://hackerone.com/reports/398799

Severity score

7.5

Reporter

jobert

Bounty paid

$4,000


Title

Information disclosure through Server side resource forgery

URL

https://hackerone.com/reports/782979

Severity score

null

Reporter

checkm50

Bounty paid

null


Title

Blind SSRF on debug.nordvpn.com due to misconfigured sentry instance

URL

https://hackerone.com/reports/756149

Severity score

null

Reporter

mase289

Bounty paid

$100


Title

[h1-415 2020] SSRF in a headless chrome with remote debugging leads to sensible information leak

URL

https://hackerone.com/reports/781295

Severity score

null

Reporter

d1r3wolf

Bounty paid

null


Title

Get-based SSRF limited to HTTP protocol on https://resizer.line-apps.com/form

URL

https://hackerone.com/reports/707014

Severity score

null

Reporter

ledz1996

Bounty paid

$1,350


Title

[h1-415 2020] Multiple vulnerabilities leading to leaking of secret user files

URL

https://hackerone.com/reports/780036

Severity score

null

Reporter

nukedx

Bounty paid

null


Title

[SSRF] Server-Side Request Forgery at https://sea-web.gold.razer.com/dev/simulator via notify_url Parameter

URL

https://hackerone.com/reports/777664

Severity score

10

Reporter

s3cr3tsdn

Bounty paid

$2,000


Title

SSRF external interaction

URL

https://hackerone.com/reports/1023920

Severity score

null

Reporter

falcon_319

Bounty paid

null


Title

Blind SSRF in Ticketing Integrations Jira webhooks leading to internal network enumeration and blind HTTP requests

URL

https://hackerone.com/reports/344032

Severity score

6.7

Reporter

ajxchapman

Bounty paid

null


Title

SSRF & unrestricted file upload on https://my.stripo.email/

URL

https://hackerone.com/reports/771382

Severity score

null

Reporter

pain45

Bounty paid

null


Title

SSRF in VCARD photo upload functionality

URL

https://hackerone.com/reports/296045

Severity score

null

Reporter

logan5

Bounty paid

$850


Title

Server-Side Request Forgery (SSRF) in Ghost CMS

URL

https://hackerone.com/reports/793704

Severity score

4.4

Reporter

whoareme

Bounty paid

null


Title

SSRF

URL

https://hackerone.com/reports/253558

Severity score

null

Reporter

linkks

Bounty paid

null


Title

SSRF in img.lemlist.com that leads to Localhost Port Scanning

URL

https://hackerone.com/reports/783392

Severity score

null

Reporter

arsene_lupin

Bounty paid

null


Title

Urllib connects to a wrong host

URL

https://hackerone.com/reports/305978

Severity score

null

Reporter

orange

Bounty paid

$500


Title

Server Side Request Forgery in Uppy npm module

URL

https://hackerone.com/reports/786956

Severity score

8.2

Reporter

eslam-shieldfy

Bounty paid

null


Title

SSRF in my.stripo.email

URL

https://hackerone.com/reports/852413

Severity score

null

Reporter

x25s

Bounty paid

null


Title

Blind SSRF on sentry.dev-my.com due to Sentry misconfiguration

URL

https://hackerone.com/reports/686363

Severity score

null

Reporter

kiriknik

Bounty paid

$500


Title

Possible SSRF in email server settings(SMTP mode)

URL

https://hackerone.com/reports/222667

Severity score

null

Reporter

xifengweiyu

Bounty paid

null


Title

Blind SSRF on image proxy camo.stream.highwebmedia.com

URL

https://hackerone.com/reports/385178

Severity score

6.5

Reporter

ninjajuju

Bounty paid

$800


Title

SSRF protection bypass in /appsuite/api/oxodocumentfilter addfile action

URL

https://hackerone.com/reports/863553

Severity score

4.9

Reporter

skr0x1c0

Bounty paid

$550


Title

Evaluating Ruby code by injecting Rescue job on the system_hook_push queue through web hook

URL

https://hackerone.com/reports/299473

Severity score

8.5

Reporter

jobert

Bounty paid

$750


Title

SSRF protection bypass

URL

https://hackerone.com/reports/736867

Severity score

6.3

Reporter

foobar7

Bounty paid

$100


Title

Server-Side Request Forgery on SAML Application - Import via URL

URL

https://hackerone.com/reports/324005

Severity score

6.1

Reporter

ziot

Bounty paid

$450


Title

SSRF on duckduckgo.com/iu/

URL

https://hackerone.com/reports/398641

Severity score

null

Reporter

d0nut

Bounty paid

null


Title

Unchecked URL in attachment datasource

URL

https://hackerone.com/reports/725307

Severity score

6.5

Reporter

zhutyra

Bounty paid

$850


Title

[city-mobil.ru] SSRF & limited LFR on /taxiserv/photoeditor/save endpoint via base64 POST parameter

URL

https://hackerone.com/reports/853068

Severity score

8.5

Reporter

byq

Bounty paid

$6,000


Title

SSRF in filtering on relap.io

URL

https://hackerone.com/reports/739962

Severity score

null

Reporter

rumiljonov

Bounty paid

$1,700


Title

Blind SSRF [ Sentry Misconfiguraton ]

URL

https://hackerone.com/reports/587012

Severity score

null

Reporter

elmahdi

Bounty paid

$250


Title

SSRF on project import via the remote_attachment_url on a Note

URL

https://hackerone.com/reports/826361

Severity score

null

Reporter

vakzz

Bounty paid

$10,000


Title

SSRF vulnerability in gitlab.com webhook

URL

https://hackerone.com/reports/301924

Severity score

null

Reporter

wuqidashi

Bounty paid

null


Title

SSRF on infawiki.informatica.com and infawikitest.informatica.com

URL

https://hackerone.com/reports/327480

Severity score

null

Reporter

0ang3el

Bounty paid

null


Title

Server Side Request Forgery mitigation bypass

URL

https://hackerone.com/reports/632101

Severity score

null

Reporter

mclaren650sspider

Bounty paid

$3,500


Title

SSRF in notifications.server configuration

URL

https://hackerone.com/reports/850114

Severity score

4.7

Reporter

codeprivate

Bounty paid

$300


Title

Server-Side Request Forgery using Javascript allows to exfill data from Google Metadata

URL

https://hackerone.com/reports/530974

Severity score

null

Reporter

nahamsec

Bounty paid

$4,000


Title

SSRF at iris.lystit.com

URL

https://hackerone.com/reports/206894

Severity score

null

Reporter

tripwire

Bounty paid

$100


Title

SSRF on jira.mariadb.org

URL

https://hackerone.com/reports/397402

Severity score

5.8

Reporter

putsi

Bounty paid

null


Title

SSRF in the application's image export functionality

URL

https://hackerone.com/reports/816848

Severity score

null

Reporter

muon4

Bounty paid

$250


Title

ssrf xspa [https://prt.mail.ru/]

URL

https://hackerone.com/reports/191543

Severity score

null

Reporter

haxta4ok00

Bounty paid

$150


Title

Чтение файлов на сервере и раскрытие директорий mediator.media

URL

https://hackerone.com/reports/411466

Severity score

5.8

Reporter

truwa

Bounty paid

$800


Title

Lack of input sanitization in Marketo form leads to execution of HTML in lead emails

URL

https://hackerone.com/reports/220009

Severity score

null

Reporter

encrypt

Bounty paid

$500


Title

SSRF на api.icq.net

URL

https://hackerone.com/reports/432277

Severity score

5.3

Reporter

theappsec

Bounty paid

$500


Title

Infrastructure - Photon - SSRF

URL

https://hackerone.com/reports/204513

Severity score

null

Reporter

skansing

Bounty paid

$350


Title

SSRF через Share-ботов

URL

https://hackerone.com/reports/197365

Severity score

null

Reporter

at3nder

Bounty paid

$300


Title

SSRF - RSS feed, blacklist bypass (301 re-direct)

URL

https://hackerone.com/reports/299135

Severity score

null

Reporter

logan5

Bounty paid

$850


Title

GET /api/v2/url_info endpoint is vulnerable to Blind SSRF

URL

https://hackerone.com/reports/1057531

Severity score

8.4

Reporter

atc_h1h1

Bounty paid

null


Title

Blind SSRF on errors.hackerone.net due to Sentry misconfiguration

URL

https://hackerone.com/reports/374737

Severity score

3.1

Reporter

chaosbolt

Bounty paid

$3,500


Title

SSRF in rompager-check

URL

https://hackerone.com/reports/374818

Severity score

null

Reporter

oreamnos

Bounty paid

null


Title

SSRF On [ allods.mail.ru ]

URL

https://hackerone.com/reports/602498

Severity score

5.8

Reporter

elmahdi

Bounty paid

$750


Title

SSRF - URL Attachments - 725307 bypass

URL

https://hackerone.com/reports/737161

Severity score

null

Reporter

zhutyra

Bounty paid

$400


Title

Potential SSRF and disclosure of sensitive site on *shopifycloud.com

URL

https://hackerone.com/reports/382612

Severity score

null

Reporter

rijalrojan

Bounty paid

null


Title

SSRF (open) - via GET request

URL

https://hackerone.com/reports/180527

Severity score

null

Reporter

firex

Bounty paid

$300