Bypass comment restriction

Disclosed: 2024-09-19 10:28:39 By retat4 To security
Medium
Vulnerability Details
Hackerone disallows people with under 3000 reputation and 3 signal to comment on reports which have been closed as informative or N/A: {F3542835} However you can bypass this and leave an infinite amount of comments by "requesting disclosure" , then cancelling it (if you want to write more messages), then request again and so on. you can attach a comment on each request/cancellation , effectively bypassing this measure {F3542836} ## Impact broken access control (bypassing restriction)
Actions
View on HackerOne
Report Stats
  • Report ID: 2679108
  • State: Closed
  • Substate: informative
  • Upvotes: 35
Share this report