No rate limiting in changing room subject.
Low
C
Chaturbate
Submitted None
Actions:
Reported by
cunn
Vulnerability Details
Technical details and impact analysis
Before i shed more light on this: I noticed i can create over 200 apps but i don't really know how valid that was.
I want to report that there is no rate limiting in changing room subject.
Attacker scenrio:
1. Navigate to https://chaturbate.com/b/your username
2. Try to create a room subject and capture the request.
3. Send to intruder and repeater it numerous times.
4. I tried this 144 times and it was succesful
Thanks
Below is a video as a poc
## Impact
bruteforcing.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved