Bypass comment restriction
Medium
Vulnerability Details
Hackerone disallows people with under 3000 reputation and 3 signal to comment on reports which have been closed as informative or N/A:
{F3542835}
However you can bypass this and leave an infinite amount of comments by "requesting disclosure" , then cancelling it (if you want to write more messages), then request again and so on. you can attach a comment on each request/cancellation , effectively bypassing this measure
{F3542836}
## Impact
broken access control (bypassing restriction)
Actions
View on HackerOneReport Stats
- Report ID: 2679108
- State: Closed
- Substate: informative
- Upvotes: 35