Glovo Program Statistics
8 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Cross-site Scripting (XSS) - Reflected
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Getting a free delivery by singing up from "[email protected]" | Privilege Escalation | cmuppin | Medium | 2022-07-11 |
| Server Side Template Injection on Name parameter during Sign Up process | Code Injection | battle_angel | High | 2022-07-11 |
| Exposed valid AWS, Mysql, Sendgrid and other secrets | Use of Hard-coded Credentials | mehdisadir | Critical | 2022-07-08 |
| Django debug enabled showing information about system, database, configuration files | Information Disclosure | omarelfarsaoui | Medium | 2022-05-31 |
| Integer overflow vulnerability | Integer Overflow | 0f1c3r | Critical | 2022-05-17 |
| chainning bugs to get full disclosure of Users addresses | Information Disclosure | spaceboy20 | Medium | 2021-11-16 |
| Reflected XSS on delivery.glovoapp.com | Cross-site Scripting (XSS) - Reflected | celesian | Medium | 2021-08-18 |
| Moodle XSS on evolve.glovoapp.com | Cross-site Scripting (XSS) - Reflected | sn3akysnak3 | Medium | 2021-05-12 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles