Leaderboard Bug Hunter
JagoanSiber

Daftar peserta yang berhasil menemukan celah keamanan pada simulasi bug hunting JagoanSiber kelas Ethical Hacking for Beginner Batch 1

Pengen jadi Ethical Hacking seperti mereka?
Gabung kelas Ethcial Hacking for Beginner Batch 2.

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Escalation via Parameter Tampering on Registration Formbertani.my.idPEHigh50
Stored Cross-Site Scriptingbertani.my.idXSSHigh50
Unrestricted Access to Administrative Interfacepegawai.my.idBACCritical100
Insecure Direct Object Reference (IDOR) on Tasks & Payrolls Endpointpegawai.my.idIDORMedium30
Information Disclosure via Publicly Accessible Environment Filepegawai.my.idSFDLow10
Unrestricted Access to Administrative Interface Ringkasin.My.Idringkasin.my.idBACCritical100
Insecure Direct Object Reference (IDOR) on Update Data Profileringkasin.my.idIDORHigh50
Insecure Direct Object Reference (IDOR) on Manage Link Endpointringkasin.my.idIDORMedium30
Privilege Escalation via Parameter Tampering on Registration Formringkasin.my.idPEHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Unauthorized Database Access via Exposed Credentialsbertani.my.idSFICritical100
Debug Mode Disclosure with Full Stack Trace (Laravel)bertani.my.idDMDLow10
Critical Privilege Escalation via Unrestricted Role Assignment in /employeepegawai.my.idPEHigh50
Insecure Direct Object Reference (IDOR) -Unauthorized Task Editingpegawai.my.idIDORHigh50
Exposed .env and db.php File Allowing Unauthorized Database Access via Sensitive File Enumerationpegawai.my.idSFDCritical100
Security Vulnerability Report: Insecure Direct Object Reference (IDOR) in User Managementringkasin.my.idIDORHigh50
Unrestricted File Upload Leading to Sensitive Data Exposure and Database Compromiseringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Broken Access Controlbertani.my.idBACHigh50
Broken Access Controlbertani.my.idBACHigh50
Cross-Site Scripting (XSS)bertani.my.idXSSHigh50
Stored Cross-Site Scripting (XSS)bertani.my.idXSSHigh50
Sensitive File Disclosurepegawai.my.idSFDLow10
Broken Access Controlringkasin.my.idBACHigh50
Sensitive Data Exposure dan Broken Access Controlringkasin.my.idSDEHigh50
Remote Code Execution (RCE) via File Uploadringkasin.my.idRCECritical100
Stored Cross-Site Scripting (XSS)ringkasin.my.idXSSMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Melakukan pendaftaran dengan mengubah user role menjadi adminbertani.my.idBACHigh50
SQL Error Exposure Due to Improper Input Validationbertani.my.idSQLiLow10
Terdapat XSS pada Diskusi Tanibertani.my.idXSSHigh50
Pemalsuan Lokasi Sisi Klien Memungkinkan Pendaftaran Kehadiran Tanpa Izinpegawai.my.idCSVBMedium30
Pengungkapan Kritis File Laravel .env Mengungkap Rahasia Aplikasi dan Kredensial Basis Datapegawai.my.idSFDLow10
Merubah role menjadi adminringkasin.my.idBACHigh50
RCE pada file upload avatar pada ringkasin.my.idringkasin.my.idRCECritical100
XSS VIA FILE UPLOADringkasin.my.idXSSMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Escalationbertani.my.idPEHigh50
Stored-Cross Site Scripting (XSS)bertani.my.idXSSHigh50
Insecure Direct Object Referencespegawai.my.idIDORMedium30
Privilege Escalationpegawai.my.idPEHigh50
Insecure Direct Object Referencesringkasin.my.idIDORHigh50
Privilege Escalationringkasin.my.idPEHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Broken Access Control pada transactions & catalogbertani.my.idBACMedium30
IDOR pada Edit Userbertani.my.idIDORHigh50
Broken Authentication/Business Logic Error pada registerbertani.my.idBAHigh50
Stored XSS (Cross Site Scripting) pada bertani.my.id/forumbertani.my.idXSSHigh50
Upload file injection to RCEringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Unauthenticated Privilege Escalation to Admin (via Role Parameter Manipulation)bertani.my.idPEHigh50
Broken Access Control (IDOR & Privilege Escalation)ringkasin.my.idBACHigh50
Remote Code Execution via Unfiltered PHP Upload in Avatar Featureringkasin.my.idRCECritical100
Stored XSS via Malicious SVG Upload in Avatarringkasin.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Stored XSS (Cross Site Scripting)bertani.my.idXSSHigh50
Sensitive Data Exposure via Exposed Environment Variable Filepegawai.my.idSDELow10
IDOR (Insecure Direct Object Reference)ringkasin.my.idIDORHigh50
Security Misconfiguration (Exposed Adminer.php / db.php)ringkasin.my.idSMLow10
Arbitrary File Upload with Impact to Remote Code Execution (RCE)ringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Insecure Direct Object References (IDOR) Vulnerability: Privilege Escalation to Admin via Registration and Settings Endpointsbertani.my.idIDORHigh50
Information Disclosure via Laravel Ignition Health Check and Potential Sensitive Management Endpoints Exposurebertani.my.idIDLow10
Information Leakage through Public Access to Sensitive Files (.env, .DS_Store, .git) and manifest.jsonpegawai.my.idILHigh50
Insecure Direct Object References (IDOR) Vulnerability: Privilege Escalation to Admin via Registration Formringkasin.my.idIDORHigh50
Persistent Cross-Site Scripting (XSS) via thread_content field at /forum pageringkasin.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Escalation melalui Manipulasi Role pada Fitur Update Profilbertani.my.idPEHigh50
Stored XSS pada Fitur Diskusi Tanibertani.my.idXSSHigh50
Remote Code Execution Vulnerabilityringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
User public bisa mendaftar/registrasi sebagai adminbertani.my.idPEHigh50
Tidak ada restriksi tipe file yang boleh diunggahbertani.my.idFRLow10
User public bisa mendaftar/registrasi sebagai adminringkasin.my.idPEHigh50
IDOR pada update profileringkasin.my.idIDORHigh50
Tidak ada restriksi tipe file yang boleh diunggahringkasin.my.idFRLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
XSS Persisten pada Form Diskusi input Konten isi yang Mengizinkan Eksekusi Script Berbahayabertani.my.idXSSHigh50
Pengungkapan Informasi Sensitif melalui File .env yang Terekspospegawai.my.idIDLow10
Remote Code Execution (RCE) melalui Unggah File dengan Ekstensi Ganda (e.g., shell.php.jpg)ringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Insecure Direct Object Reference (IDOR)bertani.my.idIDORMedium30
Privilege Escalationbertani.my.idPEHigh50
Cross-Site Scripting (XSS)bertani.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Unauthorized Role Elevation (Petani - Admin)bertani.my.idPEHigh50
Cross Site Scripting (XSS) in Diskusi Modulebertani.my.idXSSHigh50
Insecure Direct Object Reference (IDOR) in Payrolls Modulepegawai.my.idIDORMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Escalation via Parameter Tampering of 'role_name' during User Registrationbertani.my.idPEHigh50
Source Code Information Disclosure via exposed git folderpegawai.my.idIDLow10
Privilege Escalation via Hidden Field Manipulation during User Registrationringkasin.my.idPEHigh50
Source Code Information Disclosure via exposed git folderringkasin.my.idIDLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
IDOR Vulnerability on bertani.my.idbertani.my.idIDORHigh50
IDOR Vulnerability on ringkasin.my.idringkasin.my.idIDORHigh50
Improper Input Validation on Telephoneringkasin.my.idIVLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
RCE via Malicious File Uploadringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Escalation - Registerbertani.my.idPEHigh50
Privilege Escalation - Admin Pathbertani.my.idPEHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Upload File Arbitrer Melalui Fitur Foto Profil Mengakibatkan Eksekusi Kode Jarak Jauh (Remote Code Execution)ringkasin.my.idRCECritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Admin Role via Mass Assignmentringkasin.my.idPEHigh50
Chained Exploit Leading to Full Admin Accessringkasin.my.idPEHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Unrestricted Upload of File with Dangerous Typeringkasin.my.idFRCritical100

Judul LaporanTarget WebsiteKategoriSeverityScore
Vertical Privilege Escalation Exploited via Burp Suite in Role Assignment Endpointbertani.my.idPEHigh50
Stored XSS in Forum Comments on bertani.my.idbertani.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
IDOR + Broken Access Control Leading to Privilege Escalation (User - Admin)bertani.my.idIDOR+PEHigh50
stored xss contained in the profile update page that is executed on the user data pagebertani.my.idXSSMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Stored Cross-Site Scripting (XSS) melalui Kolom 'Pekerjaan' pada Fitur Update Profil Penggunabertani.my.idXSSHigh50
Insecure Direct Object Reference (IDOR) pada Fitur Pemendek URLringkasin.my.idIDORMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Stored Cross-Site Scripting (XSS)bertani.my.idXSSHigh50
Sensitive Data Exposure pada pegawai.my.idpegawai.my.idSDEMedium30

Judul LaporanTarget WebsiteKategoriSeverityScore
Critical SQL Injection & Stored XSS on bertani.my.idbertani.my.idSQLi+XSSMedium30
Critical Disclosure - Exposed .git & .env on pegawai.my.idpegawai.my.idIDLow10
Email Enumeration via Forgot Passwordpegawai.my.idIDLow10
Disclosure Of Internal Configuration Via Exposed Web.Configringkasin.my.idIDLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
Pengungkapan Informasi Sensitif Melalui Pesan Error Laravel yang Terlalu Rincibertani.my.idIDLow10
Stored XSS pada Fitur Forum di bertani.my.idbertani.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
XSS to Session Hijacking via Insecure Cookies (Missing HttpOnly & Secure Flags)bertani.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Stored Cross-Site Scripting (XSS) in Forum Modulebertani.my.idXSSHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Privilege Encapsulation via register pageringkasin.my.idPEHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Laporan bug broken access control di webringkasin.my.idBACHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Broken Access Controlbertani.my.idBACHigh50

Judul LaporanTarget WebsiteKategoriSeverityScore
Host Header Injection Leading to Open Redirectbertani.my.idHHILow10
Host Header Injection Leading to Full Website Open Redirect on bertani.my.idbertani.my.idHHILow10
Host Header Injection Causes Open Redirection of Website Login and Register Formsringkasin.my.idHHILow10

Judul LaporanTarget WebsiteKategoriSeverityScore
Vulnerability Disclosureringkasin.my.idVDLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
Adminer Terbuka untuk Publik di https://ringkasin.my.idringkasin.my.idIDLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
Broken Access Control pada Halaman Transaksi - Akses Tanpa Autentikasi & Eksekusi Aksi Sensitifbertani.my.idBACLow10

Judul LaporanTarget WebsiteKategoriSeverityScore
SQL Injectionbertani.my.idSQLiLow10