writeups.xyz writeups.xyz / Mohsin Khan (@Tabaahi_)

Title Vulnerabilities Programs Authors
A business Logic issue worth $1500
Account verification code bypass lead to a $4000 bounty
Full account takeover worth $1000 Think out of the box
IDOR via Websockets allow me to takeover any users account