Loading HuntDB...

Bypassing x profile verification to receive instant blue checkmark and unlimited profile changes

Low
X
X (Formerly Twitter)
Submitted None

Team Summary

Official summary from X (Formerly Twitter)

It was possible to bypass the profile verification check on verified accounts while making profile updates, leading to unlimited profile changes.

Reported by itsdavid

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
By upgrading your plan to the new premium+ plan immediately after your profile pic changes you can sidestep the review process allowing users to continously change their profile pictures without them being reviewed. You can do this upgrading and downgrading the plans. I have detailed this in a thread on x here. ██████████ I did try to reach out but couldn't find a support for that fit this criteria. ## Impact This is not an attach point but it is however a way of bypassing the system and safe guards x have in place to potentially allow malicious profile pictures that avoid the review process.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$250.00

Submitted

Weakness

Business Logic Errors