I just found my first bug bounty vulnerability 🎯
An e-learning platform was giving full premium access
($399 subscription) without collecting payment.
Just 3 API calls. No hacking tools.
Just logic. 🧠
Reported it. Doing my part to make the web safer 🤝
#BugBounty#HackerOne
🎉 Just found my first vulnerability ever!A CORS misconfiguration Access Control Allow Credentials: true reflecting arbitrary origins.
Excited... until I saw "Duplicate"
The bug was already reported back in 2024 and still alive after 2 years!Not the win I wanted
#BugBounty
@loop0420 Thanks for the feedback. I understand the concern about missing impact. I’ll re-evaluate the PoC and try to demonstrate a clearer security impact if there is one.
@pngweb3 Struggling to understand whether this is satire or not. On the chanve it isn't, you didnt provide a PoC that shows impact. Misconfig CORS can be fantastic if it actually works lol, means nothing if not.
Did I hear someone say AI slop? we call it "AIcurracy" 15 new findings today alone, found and reported by @BugBunny_ai@Hacker0x01 is about to get tired of seeing the bunny notifications. 🥕