Loading HuntDB...

X (Formerly Twitter) - HackerOne Reports

View on HackerOne
164
Total Reports
14
Critical
24
High
56
Medium
25
Low
Weakness: Privacy Violation
Weakness: Cross-site Scripting (XSS) - Generic

CSRF on cards API

Reported by: filedescriptor | Disclosed:
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Information Disclosure
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: UI Redressing (Clickjacking)
Critical
Weakness: Business Logic Errors
Weakness: Privacy Violation
Bounty: $2940.00
Critical
Weakness: Business Logic Errors
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Information Disclosure
Weakness: Improper Authentication - Generic
Bounty: $280.00
Weakness: Information Disclosure
Bounty: $560.00
Weakness: Improper Authentication - Generic
Weakness: Insufficient Session Expiration
Bounty: $560.00
Weakness: Uncontrolled Resource Consumption
Previous Page 2 of 9 Next