No rate limit in affiliate statsapi endpoint
Low
C
Chaturbate
Submitted None
Actions:
Reported by
maximus-decimus-meridius
Vulnerability Details
Technical details and impact analysis
##Brute force at affiliate statsapi##
## Steps To Reproduce:
1. The affiliate stats api link is vulnerable to brute force
https:// chaturbate.com/affiliates/apistats/?username=hackeronetestchat&token=**vulnerable**
I've used my profile and and my token to check brute force
The correct token returned with 200 ok status
## Impact
An attacker could view the affiliates stats of an user
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Restriction of Authentication Attempts