Dark C0d3rs
HackerOne Disclosed Reports - 2025-05-09 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2025-05-09 (/Thread-HackerOne-Disclosed-Reports-2025-05-09)



HackerOne disclosed reports - 2025-05-09 - hashXploiter - 05-10-2025

Logo
Medium
resolved

Race condition on add 1 free domain


Bug reported by ASC Lages was disclosed at May 9, 2025, 6:59 pm   |   Business Logic Errors

A race condition vulnerability was discovered on the Gravatar platform, which allowed users to bypass the limitation of claiming only one free custom domain. The vulnerability was triggered by creating multiple parallel requests to the public-api.wordpress.com endpoint, where the "meta" parameter was modified, leading to the acquisition of more than one free domain.