Loading HuntDB...

Nextcloud - HackerOne Reports

View on HackerOne
508
Total Reports
10
Critical
46
High
173
Medium
179
Low
Weakness: Improper Authentication - Generic
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Uncontrolled Resource Consumption
Weakness: Code Injection
Bounty: $100.00

Drone Nextcloud

Reported by: rbcafe | Disclosed:
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Uncontrolled Resource Consumption
Weakness: Improper Restriction of Authentication Attempts
Bounty: $750.00
Medium
Weakness: Cross-site Scripting (XSS) - Generic
Medium
Weakness: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Weakness: Code Injection

Email Spoofing

Reported by: khalidamin | Disclosed:
Weakness: Violation of Secure Design Principles
Weakness: Improper Authentication - Generic
Weakness: Cleartext Transmission of Sensitive Information

Bypassing lock protection

Reported by: doragon | Disclosed:
Low
Weakness: Improper Authentication - Generic
Bounty: $50.00
Weakness: Improper Authentication - Generic
Weakness: Information Disclosure
Bounty: $100.00
Weakness: Violation of Secure Design Principles
Weakness: Improper Access Control - Generic
Bounty: $250.00
Page 1 of 26 Next