Missing Rate Limiting on https://twitter.com/account/complete

Disclosed: 2014-11-10 20:10:50 By surgent10cross To x
Unknown
Vulnerability Details
The following link is missing rate limiting https://twitter.com/account/complete by which an attacker can get all the valid phone no. on twitters account. ##POC :- Screenshot attached
Actions
View on HackerOne
Report Stats
  • Report ID: 27166
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report