Loading HuntDB...

Missing Rate Limitation at /photo_videos/photoset/create

Low
C
Chaturbate
Submitted None
Reported by m00hdi

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
Hello,I discovered that one is able to create an unlimited number of albums Via /photo_videos/photoset/create/ Steps To Reproduce: 1.Login And Go to http://fr.chaturbate.co /photo_videos/photoset/create/ 2.Fill the form 3.Enable a proxy interception tool (e.g Burp Suite) 4.Click Save 5.Send the POST request made to /photo_videos/photoset/create to intruder 6.Set 500 or more custom inputs and Start attack I've been able to create many albums without restrictions Reference: F364058 ## Impact Create an unlimited number of albums

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors