Loading HuntDB...

No rate limit on app.crowdsignal.com (Finish quiz)

Low
A
Automattic
Submitted None
Reported by yusuf_furkan

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
Hello team [https://hackerone.com/reports/488923 ]--> vulnerability resolved maybe you can compare the report to start this, but this vulnerability has been closed.this is a separate no-rate limit error.this is not a duplicate bug. No rate limit on app.crowdsignal.com (Finis quiz) POC step: 1.https://app.crowdsignal.com/quizzes/new 2.example (https://testedtestsdasad1404.survey.fm/untitled-quiz-1) 3.Finish quiz send it to Intruder.(Burp suite) 4.get the payloads ready. Attack with null payloads. 5.POC video and screenshot: ## Impact an attacker could send a large number of requests to terminate the victim. there is a limit.(quiz finish) solution: a limit must be added.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors