Tennessee Valley Authority Program Statistics
11 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Cross-site Scripting (XSS) - Reflected
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| File listing through scripts folder | File and Directory Information Exposure | itssixtynein | No rating | 2024-02-09 |
| access to profile & reset password page without authentication | Improper Authentication - Generic | mohs3n | Medium | 2023-11-30 |
| captcha bypass leads to register multiple user with one valid captcha | Business Logic Errors | mohs3n | Medium | 2023-11-30 |
| internal path disclosure via register error | Information Exposure Through an Error Message | mohs3n | Low | 2023-11-30 |
| Incorrect Authorization leads to see other users Documents Uploaded | Incorrect Authorization | mohs3n | Medium | 2023-11-30 |
| Admin.MyTVA.com Customer lookup and internal notes bypass | Authentication Bypass Using an Alternate Path or Channel | itssixtynein | Medium | 2023-10-13 |
| xss reflected - pqm.tva.com | Cross-site Scripting (XSS) - Reflected | thiagomarques | Medium | 2023-10-13 |
| No Rate Limit On Forgot Password Page | None supplied | sailesh01nik | Low | 2023-09-11 |
| xss reflected - pq.tva.com | Cross-site Scripting (XSS) - Reflected | thiagomarques | Medium | 2023-09-11 |
| Rate limit missing sign-in page | Improper Restriction of Authentication Attempts | dreamer_eh | Medium | 2023-07-11 |
| SQL Injection on https://soa-accp.glbx.tva.gov/ via "/api/" path - VI-21-015 | SQL Injection | yassinek3ch | Critical | 2022-04-26 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles