get-request-vulnerability

2 articles
sort: new top best
clear filter
0 5/10

A CSRF vulnerability in Instagram's copyright dispute feature allowed attackers to delete users' media via a simple GET request to an unauthenticated endpoint, exploitable through social engineering. The vulnerability was discovered in January 2019 and patched within days, with a $3,000 bounty awarded.

Instagram Facebook Pouya $3,000
blog.darabi.me · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details
0 2/10
bug-bounty

A bug bounty hunter shares four low-impact CSRF vulnerabilities found across private programs, including cart spam via public wishlist functionality, referer header bypass techniques, unprotected API endpoints, and favorite list deletion—all with minimal technical depth and bounty amounts ($25 or swag).

Navneet HackerOne IBM
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details