Loading HuntDB...

Moderators can send messages to users from banned subreddits via `oauth.reddit.com/api/mod/conversations`

Low
R
Reddit
Submitted None
Reported by ba-reynolds

Vulnerability Details

Technical details and impact analysis

Improper Input Validation
## Summary: It is possible for moderators to send messages to users from a banned subreddit. I assume this is not intended considering that when trying to send a message as a banned subreddit via [reddit.com/message/compose](https://www.reddit.com/message/compose) (`from` field) you get a `200` response but the message is never delivered to the recipient. ## Steps To Reproduce: 1. While in [mod.reddit.com/mail/create](https://mod.reddit.com/mail/create), select a banned subreddit from the dropdown menu. 2. Fill in all other fields and send the message. ## Impact Moderators can "officially" communicate with users even after the subreddit gets banned. This can be used to organize a new subreddit to migrate to in order to circumvent the ban.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Improper Input Validation