![]() |
|
HackerOne Disclosed Reports - 2025-05-09 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-05-09 (/Thread-HackerOne-Disclosed-Reports-2025-05-09) |
HackerOne disclosed reports - 2025-05-09 - hashXploiter - 05-10-2025
Medium
resolved Race condition on add 1 free domainBug reported by ASC Lages was disclosed at May 9, 2025, 6:59 pm | Business Logic Errors A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain. |