Bug Hunting 9
- 1-Click Account Takeover (ATO) in Voox Android
- 2FA Bypass via Response Manipulation -- Binding MFA Without Email Verification
- Bypassing OTP Rate Limits with a Simple Capital Letter
- S3 Bucket Writeable and Readable by Unauthenticated Users
- The Thrilling Hunt for a Boolean-Based Blind SQL Injection
- Stored XSS to Account Takeover on Web3
- Exposing Broken Access Control in Salesforce
- Improper Access Control: User Information Exposure
- Open Redirect To Account TakeOver