Disclosures

2022

Aug 05
[#004] CVE-2022-35953 - Tabnabbing via window.opener [bookwyrm.social]
Aug 06
[#003] CVE-2022-2821 - Account Takeover [namelessmc.com]
Aug 06
[#002] CVE-2022-2820 - Previously created sessions continue being valid after MFA activation

2020

Sep 17
[#001] OTP BYPASS THROUGH RESPONSE MANIPULATION - Private Bugcrowd Program