Waitlist bypass for accessing SIGN.PLUS Beta
Low
A
Alohi
Submitted None
Team Summary
Official summary from Alohi
During SIGN.PLUS beta phase, it was found out that hackers could trick the API response and pretend to have been accepted into the beta program. All server operations would be blocked, but the UI client would be accessible, exposing the work-in-progress design to non-beta users. There was no consequence as SIGN.PLUS was to be released to the public a couple of days later.
Actions:
Reported by
darkknight4688
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic