Bypass captcha count creation issues

HackerOne report #700670 by iframe on 2019-09-24, assigned to @jeremymatos:

Hi, I noticed that in Issues there is a captcha for creation
xx1.png

I wondered why the project administrator has it, and I decided to get around it

CSV file import function does not have captcha at all

I made a request:
request.txt

As a result, I was able to make a lot of discussions without a single captcha, in addition, each created discussion came to my mail + one more error
___.png

Impact

Bypass captcha count count creation discussions

Attachments

Warning: Attachments received through HackerOne, please exercise caution!

  • xx1.png
  • request.txt
  • ___.png
Assignee Loading
Time tracking Loading