Unrestricted File Upload on https://app.dropcontact.io/app/upload/
https://hackerone.com/reports/949295
null
omarelfarsaoui
null
Unrestricted File Upload on https://my.stripo.email and https://stripo.email
https://hackerone.com/reports/823588
null
doctor_spooky
null
Unrestricted file upload when creating quotes allows for Stored XSS
https://hackerone.com/reports/788397
5.2
m0chan
$250
Stored XSS on ████████helpdesk
https://hackerone.com/reports/901799
null
atbabers
null
Theme Assets uploader allows HTML content
https://hackerone.com/reports/769998
null
nightmare_msf
$100
Unrestricted file upload leads to Stored XSS
https://hackerone.com/reports/808862
null
semsem123
$250
Tricking the "Create snippet" feature into displaying the wrong filetype can lead to RCE on Slack users
https://hackerone.com/reports/833080
8.7
mcsheehan
$1,500
Unrestricted File Upload Leads to XSS & Potential RCE
https://hackerone.com/reports/900179
null
pi_hunter50
null
File upload vulnerability on a DoD website
https://hackerone.com/reports/191243
null
korprit
null
Unrestricted File Upload on https://app.lemlist.com
https://hackerone.com/reports/722919
null
ctulhu
null