Rate Limit Bypass via X-Forwarded-For Header Manipulation on Registration Page

Disclosed by
ShahwarShah
  • Engagement YNAB
  • Disclosed date over 1 year ago
  • Reward $150
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by ShahwarShah

I Found Rate Limit Bypass via X-Forwarded-For Header Manipulation on Registration Page at YNAB on Bugcrowd which was fixed and i got rewarded

Activity