Loading HuntDB...

Waitlist bypass for accessing SIGN.PLUS Beta

Low
A
Alohi
Submitted None

Team Summary

Official summary from Alohi

During SIGN.PLUS beta phase, it was found out that hackers could trick the API response and pretend to have been accepted into the beta program. All server operations would be blocked, but the UI client would be accessible, exposing the work-in-progress design to non-beta users. There was no consequence as SIGN.PLUS was to be released to the public a couple of days later.

Reported by darkknight4688

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic