Loading HuntDB...

No rate limit in affiliate statsapi endpoint

Low
C
Chaturbate
Submitted None

Vulnerability Details

Technical details and impact analysis

Improper Restriction of Authentication Attempts
##Brute force at affiliate statsapi## ## Steps To Reproduce: 1. The affiliate stats api link is vulnerable to brute force https:// chaturbate.com/affiliates/apistats/?username=hackeronetestchat&token=**vulnerable** I've used my profile and and my token to check brute force The correct token returned with 200 ok status ## Impact An attacker could view the affiliates stats of an user

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Restriction of Authentication Attempts