P3 – Panel Admin Takeover via Credential Leak on API Documentation Link
P1 – RCE Via Upload PDF File
P1 – RCE Via Upload PDF File
P1 – Time Based Blind SQL Injection on search parameter
P1 – Time Based Blind SQL Injection on search parameter
P2 – IDOR For Wallet Balance Manipulation
P2 – IDOR For Wallet Balance Manipulation
P1 – Default Credential on Username Password Employer
P1 – Default Credential on Username Password Employer
P3 – Website Not Implement Email Verify (2000$)
P3 – Website Not Implement Email Verify (2000$)
Misconfig on Try Wrong Password Lead To DoS
Misconfig on Try Wrong Password Lead To DoS
[Tips] P2 – Bypass Code Verification (Bypassed System)
[TIPS] P2 – BYPASS CODE VERIFICATION
[Tips] Open Redirect to ATO via Google and Facebook OAuth
[TIPS] OPEN REDIRECT TO ATO VIA GOOGLE AND FACEBOOK OAUTH
[Tips] Bypass Insecure Direct Object Reference (IDOR) Protection
[TIPS] BYPASS INSECURE DIRECT OBJECT REFERENCE (IDOR) PROTECT