Loading HuntDB...

Nextcloud - HackerOne Reports

View on HackerOne
508
Total Reports
10
Critical
46
High
173
Medium
179
Low
Low
Weakness: Plaintext Storage of a Password
Weakness: Privilege Escalation
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Violation of Secure Design Principles

IDOR - Disable sharing

Reported by: dalt4sec | Disclosed:
Low
Weakness: Privilege Escalation
Weakness: Improper Access Control - Generic
Weakness: Violation of Secure Design Principles
Bounty: $50.00
Weakness: Code Injection
Weakness: Code Injection
Bounty: $100.00
Weakness: Server-Side Request Forgery (SSRF)
Weakness: Improper Access Control - Generic
Bounty: $1000.00
Weakness: Improper Authentication - Generic

Username Enumeration

Reported by: ahpaleus | Disclosed:
Low
Weakness: Information Disclosure
Weakness: Uncontrolled Resource Consumption
Bounty: $250.00
Weakness: SQL Injection
Weakness: Improper Certificate Validation
Bounty: $1000.00
Weakness: Uncontrolled Resource Consumption
Previous Page 5 of 26 Next