In-app reader
Quick story; I have found a really important bug which is bypassing password AND email verification for downloading a file in the app. But then, you need to have a link OF the download URL (It doesn't have a password with the URL or anything like that, the verification happens once you open) So now my problem is in the past 2 reports, I had IDOR and other important stuff but they had marked it informative because you just needed a UUID of the victim, which is permanent and never changes. And I proved to them with over 6 examples from just a google dorking method and told them about possible email breaches. They still weren't convinced EVEN if it was literally full IDOR. And It's the same program, I am afraid they will also mark this one informative. What do you think? submitted by /u/spicy_tables [link] [comments]
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.