Loading HuntDB...

TikTok - HackerOne Reports

View on HackerOne
117
Total Reports
5
Critical
18
High
50
Medium
43
Low
Weakness: Insufficient Session Expiration
Bounty: $50.00
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Information Disclosure
Bounty: $100.00
Weakness: Authentication Bypass Using an Alternate Path or Channel
Bounty: $12000.00
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Information Disclosure
Low
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Insecure Direct Object Reference (IDOR)

RCE on TikTok Ads Portal

Reported by: freesec | Disclosed:
Critical
Weakness: Code Injection
Weakness: Improper Restriction of Authentication Attempts
Weakness: CRLF Injection
Weakness: Business Logic Errors
Bounty: $1000.00

CSRF Account Takeover

Reported by: s3c | Disclosed:
High
Weakness: Cross-Site Request Forgery (CSRF)
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Cross-site Scripting (XSS) - DOM
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $3000.00
Previous Page 2 of 6 Next