X (Formerly Twitter) - HackerOne Reports
View on HackerOne164
Total Reports
14
Critical
24
High
56
Medium
25
Low
Read-only application can publish/delete fleets
Reported by:
ryotak
|
Disclosed:
Medium
Weakness: Privilege Escalation
Improper santization of edit in list feature at twitter leads to delete any twitter user's list cover photo.
Reported by:
greytesla
|
Disclosed:
Medium
Weakness: Insecure Direct Object Reference (IDOR)
Bounty: $560.00
Remote 0click exfiltration of Safari user's IP address
Reported by:
max2x
|
Disclosed:
Medium
Weakness: Forced Browsing
Bounty: $560.00
OS Command Execution on User's PC via CSV Injection
Reported by:
cornerpirate
|
Disclosed:
Medium
Weakness: OS Command Injection
Previous
Page 9 of 9