Loading HuntDB...

[www.stripo.email] There is no rate limit for contact-us endpoints

Low
S
Stripo Inc
Submitted None
Reported by what_web

Vulnerability Details

Technical details and impact analysis

Improper Authorization
###Summary The speed limit for the *https://stripo.email/es/contact-us* endpoint has not been implemented. ###Steps To Reproduce 1. Go to the *https://stripo.email/es/contact-us* 2. Turn on blocking and fill out the contact form 3. Send request to Intruder. 4. Set your payloads and start attack. 5. There is no rate-limit. ###Proof of Concept {F799307} ###Fix Implement 429 status code for too many requests. ## Impact There is no rate limit for submitting an inquiry form.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authorization