p1-vulnerability

2 articles
sort: new top best
clear filter
0 5/10

A P1 RCE vulnerability discovered in a misconfigured Jenkins instance via Shodan reconnaissance, exploiting open user registration and exposed script console execution capabilities.

Shodan Jenkins sw33tLie
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A researcher discovered a P1 account takeover vulnerability by bypassing CSRF protections on a password change endpoint through server-side validation bypass—using a random email address format instead of the victim's actual email allowed successful password changes without requiring the victim's email in the CSRF payload.

Lady Secspeare Bugcrowd
ladysecspeare.wordpress.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details