Posts tagged with #writeups
-
🔒 CVSS 6.4 Search Algorithm Manipulation on LinkedIn
1000 rvfet
Affected Company:LinkedInHow I discovered and responsibly reported an on-site and off-site search poisoning vulnerability that leads to indistinguishable user deception attacks on LinkedIn.
-
🔒 CVSS 8.1 Permanent State Corruption in Linear.app
1000 rvfet
Affected Company:Linear.appDiscovering a logic vulnerability that allowed any authenticated user to permanently brick workspaces in Linear. Used by OpenAI, Scale, and Perplexity.
-
🔒 CVSS 5.8 Google Infrastructure Exhaustion Vulnerability
1000 rvfet
Affected Company:GoogleHow I discovered a Severity 2 Zero Attribution Risk vulnerability in Google Image Proxy that could be exploited to exhaust Google's Infrastructure.
-
CVSS 9.6 Account Takeover in Azerbaijan's Most Visited Platforms
1000 rvfet
Affected Companies:tap.az ,turbo.azHow an OAuth token leakage through Open Redirect enabled complete account takeover on tap.az and turbo.az. A case study on critical vulnerabilities and exemplary vendor response by Digital Classifieds MMC.