Moderators can send messages to users from banned subreddits via `oauth.reddit.com/api/mod/conversations`
Low
R
Reddit
Submitted None
Actions:
Reported by
ba-reynolds
Vulnerability Details
Technical details and impact analysis
## Summary:
It is possible for moderators to send messages to users from a banned subreddit.
I assume this is not intended considering that when trying to send a message as a banned subreddit via [reddit.com/message/compose](https://www.reddit.com/message/compose) (`from` field) you get a `200` response but the message is never delivered to the recipient.
## Steps To Reproduce:
1. While in [mod.reddit.com/mail/create](https://mod.reddit.com/mail/create), select a banned subreddit from the dropdown menu.
2. Fill in all other fields and send the message.
## Impact
Moderators can "officially" communicate with users even after the subreddit gets banned. This can be used to organize a new subreddit to migrate to in order to circumvent the ban.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$100.00
Submitted
Weakness
Improper Input Validation