Token leak in security challenge flow allows retrieving victim's PayPal email and plain text password
https://hackerone.com/reports/739737
8
alexbirsan
$15,300
Administration page visible without authentication
https://hackerone.com/reports/809357
null
mrmj777
$100
[c-api.city-mobil.ru] Client authentication bypass leads to information disclosure
https://hackerone.com/reports/772118
9.7
act1on3
$8,000