Finding a easy p4 it can be worth 200$

2 months ago 37
BOOK THIS SPACE FOR AD
ARTICLE AD

Finding a easy p4 it can be worth 200$

bug name : lack of password confirmation leads to account deletion

it’s p4 vulnerability category by bugcrowd

Now let’s see how can we find this

Create a account with required details

after go to your profile section

after click on delete profile/delete account button

click on delete

if it’s deleted your account without asking password ..

Congrats there is a chance to get paid a easy bounty….

after deleting account try to login with the old credentials for checking account is deleted on not

you can see account was deleted ..

create poc and just report and relax …

Thanks for reading…

..Jai Shree Ram..

..Jai Shree Krishna..

..Jai Hind..

Read Entire Article