Crowdsource Success Story: From an Out-of-Scope Open Redirect to CVE-2020-1323
Blog post from Detectify
Özgür Alp, an experienced ethical hacker with over seven years in offensive security, successfully uncovered a significant vulnerability by transforming an open redirect issue into a publicly disclosed vulnerability, CVE-2020-1323, with the support of the Detectify Crowdsource team. Initially discovered during a routine bug bounty program, the vulnerability was linked to Microsoft SharePoint but was initially deemed out-of-scope by Microsoft due to the low impact nature of URL redirects. Persistence paid off when Alp reported the finding to Detectify, a platform that accepts open redirect reports irrespective of the vendor. This led to the development of a live module and a coordinated effort for responsible disclosure with Microsoft, resulting in the bug being patched and recognized with a CVE assignment. Despite Microsoft's initial assessment, collaboration ultimately led to a $1200 bounty, showcasing the value of persistence and teamwork in vulnerability disclosure.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.