Loading HuntDB...

No Rate Limit on CrowdSignal Polls when Adding Comment

Low
A
Automattic
Submitted None
Reported by bugra

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
Hi team! I hope this isn't duplicate :/ I created a poll on CrowdSignal.com (https://poll.fm/10226924) When adding a comment, there is no rate limit. You can see my comments on my poll. 1. Go to any poll. 2. Turn on Intercept and Add a Comment. 3. Send request to Intruder. 4. Set your payloads and start attack. There is no rate-limit. ## Impact No rate-limit on comments.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors