Eternal Program Statistics


View program

21 total issues disclosed

$3,150 total paid publicly

Most disclosed (4 disclosures) — Business Logic Errors



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Attacker shall recieve order updates on whatsapp for users who have activated whatsapp notification Business Logic Errors schutzx0r Medium 2022-04-06
Add upto 10K rupees to a wallet by paying an arbitrary amount Business Logic Errors ashoka_rao High 2022-02-23
Claiming the listing of a non-delivery restaurant through OTP manipulation Improper Authorization ashoka_rao Critical 2022-02-22
Page has a link to google drive which has logos and a few customer phone recordings Cleartext Storage of Sensitive Information codersanjay Medium 2022-02-21
Race condition in User comments Likes Violation of Secure Design Principles 0xdekster Low 2022-02-09
subdomain takeover on fddkim.zomato.com Privilege Escalation mosec9 Medium 2022-01-27
HTML Injection @ /[restaurant]/order endpoint. Cross-site Scripting (XSS) - Generic mr_edwards Low 2021-09-07
Lack of Password Confirmation for Account Deletion Violation of Secure Design Principles cybrot None 2020-08-11
The vulnerabilities found were XSS, Public disclosure, Network enumeration via CSRF, DLL hijacking. Cross-Site Request Forgery (CSRF) b71728d7009b6664f0e2350 No rating 2020-07-21
Mathematical error found in meals for one Business Logic Errors nikhar123 None 2020-04-29
Free food bug done by burp suite Man-in-the-Middle joker7889 None 2019-12-26
Zomato Map server going out of memory while resizing map image Heap Overflow mchinmoy None 2019-12-05
Self-Stored XSS - Chained with login/logout CSRF Cross-site Scripting (XSS) - Stored madguyyy Medium 2019-07-03
Open AWS S3 bucket leaks all Images uploaded to Zomato chat Improper Authentication - Generic yashrs Medium 2019-05-01
Bypassing the SMS sending limit for download app link. Improper Restriction of Authentication Attempts bihari_web Low 2019-04-16
Sending Unlimited Emails to anyone from zomato mail server. Improper Restriction of Authentication Attempts bihari_web None 2019-04-16
credentials leakage in public lead to view dev websites Information Disclosure xsam Low 2019-03-18
Open Redirect On Your Login Panel Open Redirect chiraggupta8769- Low 2019-02-14
Improper validation allows user to unlock Zomato Gold multiple times at the same restaurant within one day Business Logic Errors dertajora Low 2019-01-28
[auth2.zomato.com] Reflected XSS at `oauth2/fallbacks/error` | ORY Hydra an OAuth 2.0 and OpenID Connect Provider Cross-site Scripting (XSS) - Reflected sudi Medium 2019-01-21
[www.zomato.com] Blind XSS in one of the Admin Dashboard Cross-site Scripting (XSS) - Stored sandeep_hodkasia No rating 2018-12-03