Unikrn Program Statistics


View program

28 total issues disclosed

$5,065 total paid publicly

Most disclosed (7 disclosures) — None supplied



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
An IDOR that can lead to enumeration of a user and disclosure of email and phone number within cashier Insecure Direct Object Reference (IDOR) miquinho High 2023-07-17
Open URL Redirection Open Redirect stark303 Medium 2021-06-28
Lack of Input sanitization leads to database Character encoding configuration Disclosure Information Exposure Through an Error Message l_user Low 2020-08-07
Open Redirection leads to redirect Users to malicious website Open Redirect bb00x None 2020-05-06
[crm.unikrn.com] Open Redirect Open Redirect root0x0 Medium 2020-04-05
Staging Rabbitmq instance is exposed to the internet with default credentials Improper Authentication - Generic albatraoz Low 2019-12-09
Rate Limit workaround in the message of the phone number verification Improper Restriction of Authentication Attempts dr_akm Medium 2019-07-26
multiple vulnerabilities on your mautic server None supplied bbc6dfb7d3878289f2f98d4 Medium 2019-07-10
Email abuse and Referral Abuse None supplied le4rner Medium 2019-06-12
[unikrn.com] Profile updated with error":true,"success":false" None supplied rbcafe No rating 2019-06-12
Full Path Disclosure None supplied bbc6dfb7d3878289f2f98d4 Medium 2019-05-29
bypass Claudflare access crm.mautic.com None supplied b4a1d31dd4acbccc47b8072 None 2019-04-05
Path Disclosure Vulnerability http://crm.******.com None supplied b4a1d31dd4acbccc47b8072 Low 2019-04-05
█████████ on CRM server without authorization None supplied b4a1d31dd4acbccc47b8072 No rating 2019-03-14
ssh: unprivileged users may hijack due to backdated ssh version open port found(███.unikrn.com) Remote File Inclusion walidhossain010 Low 2019-03-04
Rate-limit protection get executed in the last stage of the registration process, allowing enumeration of existing account. Violation of Secure Design Principles tolo7010 Low 2018-05-03
CSRF logs the victim into attacker's account Cross-Site Request Forgery (CSRF) albatraoz Medium 2018-04-19
CSRF log victim into the attacker account Cross-Site Request Forgery (CSRF) tolo7010 High 2018-04-10
session_id is not being validated at email invitation endpoint Cross-Site Request Forgery (CSRF) tolo7010 No rating 2018-04-10
CSRF in Raffles Ticket Purchasing Cross-Site Request Forgery (CSRF) tolo7010 High 2018-04-10
Non-Cloudflare IPs allowed to access origin servers Information Disclosure moritz30 Medium 2018-02-07
Persistent XSS found on bin.pinion.gg due to outdated FlowPlayer SWF file with Remote File Inclusion vulnerability. Cross-site Scripting (XSS) - Generic sp1d3rs Low 2017-10-05
Weak Session ID Implementation - No Session change on Password change Insufficient Session Expiration wdem Medium 2017-10-05
Improper validation at Phone verification (possible cost increase + SMS SPAM attack) Violation of Secure Design Principles nitesculucian Low 2017-09-24
Flash CSRF: Update Ad Frequency %: [cp-ng.pinion.gg] Cross-Site Request Forgery (CSRF) geekboy Medium 2017-09-06
Escaping images directory in S3 bucket when saving new avatar, using Path Traversal in filename Path Traversal sp1d3rs Medium 2017-08-23
HTML injection in email in unikrn.com Command Injection - Generic coreyd97 High 2017-08-23
Urgent: Server side template injection via Smarty template allows for RCE Code Injection yaworsk No rating 2017-08-17