No rate limit on app.crowdsignal.com (Finish quiz)

Disclosed: 2019-07-27 09:01:50 By yusuf_furkan To automattic
Low
Vulnerability Details
Hello team [https://hackerone.com/reports/488923 ]--> vulnerability resolved maybe you can compare the report to start this, but this vulnerability has been closed.this is a separate no-rate limit error.this is not a duplicate bug. No rate limit on app.crowdsignal.com (Finis quiz) POC step: 1.https://app.crowdsignal.com/quizzes/new 2.example (https://testedtestsdasad1404.survey.fm/untitled-quiz-1) 3.Finish quiz send it to Intruder.(Burp suite) 4.get the payloads ready. Attack with null payloads. 5.POC video and screenshot: ## Impact an attacker could send a large number of requests to terminate the victim. there is a limit.(quiz finish) solution: a limit must be added.
Actions
View on HackerOne
Report Stats
  • Report ID: 568832
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report