No rate limit on app.crowdsignal.com (Finish quiz)
Low
A
Automattic
Submitted None
Actions:
Reported by
yusuf_furkan
Vulnerability Details
Technical details and impact analysis
Hello team
[https://hackerone.com/reports/488923 ]--> vulnerability resolved maybe you can compare the report to start this, but this vulnerability has been closed.this is a separate no-rate limit error.this is not a duplicate bug.
No rate limit on app.crowdsignal.com (Finis quiz)
POC step:
1.https://app.crowdsignal.com/quizzes/new
2.example (https://testedtestsdasad1404.survey.fm/untitled-quiz-1)
3.Finish quiz send it to Intruder.(Burp suite)
4.get the payloads ready. Attack with null payloads.
5.POC video and screenshot:
## Impact
an attacker could send a large number of requests to terminate the victim. there is a limit.(quiz finish)
solution:
a limit must be added.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors