Loading HuntDB...

Bypass comment restriction

Medium
H
HackerOne
Submitted None
Reported by retat4

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
Hackerone disallows people with under 3000 reputation and 3 signal to comment on reports which have been closed as informative or N/A: {F3542835} However you can bypass this and leave an infinite amount of comments by "requesting disclosure" , then cancelling it (if you want to write more messages), then request again and so on. you can attach a comment on each request/cancellation , effectively bypassing this measure {F3542836} ## Impact broken access control (bypassing restriction)

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Improper Access Control - Generic