Bypass comment restriction
Medium
H
HackerOne
Submitted None
Actions:
Reported by
retat4
Vulnerability Details
Technical details and impact analysis
Hackerone disallows people with under 3000 reputation and 3 signal to comment on reports which have been closed as informative or N/A:
{F3542835}
However you can bypass this and leave an infinite amount of comments by "requesting disclosure" , then cancelling it (if you want to write more messages), then request again and so on. you can attach a comment on each request/cancellation , effectively bypassing this measure
{F3542836}
## Impact
broken access control (bypassing restriction)
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Access Control - Generic