Public
Mavenlink
bug reports.
4,419
Bug Reports -
$2,030,173
Paid Out
Last Updated:
12th September, 2017
Team
Bounty
Title
Mavenlink
$50
Tabnabbing via Window.Opener @Mavenlink
Mavenlink
$25
Open/Unvalidated Redirect Issue
Mavenlink
$100
XSS in https://app.mavenlink.com/workspaces/
Mavenlink
-
Email field filtering problem.
Mavenlink
-
DNS load balancing not enabled
Mavenlink
$50
privilege escalation
Mavenlink
-
Cookies are not cleared from Server side on Logout
Mavenlink
$200
Flash XSS on swfupload.swf showing at app.mavenlink.com
Mavenlink
$50
Clickjacking
Mavenlink
$100
Login CSRF
Mavenlink
$50
Non Validation of session after password reset
Mavenlink
$100
Password reset token not expiring
Mavenlink
$50
Clickjacking at https://www.mavenlink.com/ main website
Mavenlink
$50
Login password guessing attack
Mavenlink
-
The web application https://mavenlink.com discloses version details of the underlying Platform / Server
Mavenlink
-
Clickjacking & CSRF attack can be done at https://app.mavenlink.com/login