P3 – Panel Admin Takeover via Credential Leak on API Documentation Link
P1 – RCE Via Upload PDF File
P1 – RCE Via Upload PDF File
P1 – Time Based Blind SQL Injection on search parameter
P1 – Time Based Blind SQL Injection on search parameter
P1 – Default Credential on Username Password Employer
P1 – Default Credential on Username Password Employer
P3 – Website Not Implement Email Verify (2000$)
P3 – Website Not Implement Email Verify (2000$)
[Tips] P2 – Bypass Code Verification (Bypassed System)
[TIPS] P2 – BYPASS CODE VERIFICATION
[Tips] P1 – Bypass IDOR Protection
[TIPS] P1 – BYPASS IDOR PROTECTION
[Tips] Open Redirect to ATO via Google and Facebook OAuth
[TIPS] OPEN REDIRECT TO ATO VIA GOOGLE AND FACEBOOK OAUTH
[Tips] Bypass Insecure Direct Object Reference (IDOR) Protection
[TIPS] BYPASS INSECURE DIRECT OBJECT REFERENCE (IDOR) PROTECT
[Tips] Bypass Fixed – ATO via Forgot Password on Mobile App
[TIPS] BYPASS FIXED – ATO VIA FORGOT PASSWORD ON MOBILE APP