Missing Rate Limitation at /photo_videos/photoset/create

Disclosed: 2018-11-24 23:09:33 By m00hdi To chaturbate
Low
Vulnerability Details
Hello,I discovered that one is able to create an unlimited number of albums Via /photo_videos/photoset/create/ Steps To Reproduce: 1.Login And Go to http://fr.chaturbate.co /photo_videos/photoset/create/ 2.Fill the form 3.Enable a proxy interception tool (e.g Burp Suite) 4.Click Save 5.Send the POST request made to /photo_videos/photoset/create to intruder 6.Set 500 or more custom inputs and Start attack I've been able to create many albums without restrictions Reference: F364058 ## Impact Create an unlimited number of albums
Actions
View on HackerOne
Report Stats
  • Report ID: 426547
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report