Permanent DoS with one click.

Disclosed: 2020-11-19 07:45:47 By asdasdasdasdasda To automattic
Medium
Vulnerability Details
## Summary: Hello Team, messages of a user who deletes their account leave DoS effects on another user. ## Platform(s) Affected: [website/mobile app/service] ## Steps To Reproduce & PoC: Before you start testing, create two accounts. [email protected] [email protected] Confirm e-mails to send messages. 1. Log into the attacker's account. 2. Message the victim from the attacker's account. 3. Delete the attacker's account. 4. Log into the victim's account. 5. Check the victim's message box. 6. The victim cannot use the account again. Video: {F978195} ## Impact The victim cannot use the account again.
Actions
View on HackerOne
Report Stats
  • Report ID: 975827
  • State: Closed
  • Substate: resolved
  • Upvotes: 126
Share this report