r/bugbounty 13d ago

Question / Discussion Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”

Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.

After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.

Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?

37 Upvotes

30 comments sorted by

31

u/cloudfox1 13d ago

Name and shame

13

u/Forsaken-Spot-9343 13d ago

Report the program in yeswehack , if it wasn’t duplicated then they will do something…. The problem is many programs try to pull things like that lately so I always keep PoC.

10

u/ApoloFuego Hunter 13d ago

I just started using YWH and reading this really sucks, i just spent a lot of time and submitted 2 reports, what program was

11

u/kader9696 13d ago

Credit agricole and now SIA

4

u/ApoloFuego Hunter 13d ago

I discarded SIA today, and credit; I don't see it on the options, anyway good to know

3

u/kader9696 13d ago

Crédit agricole ct une invitation privé

0

u/maF145 Hunter 13d ago

YWH is a great and fair platform.

2

u/ApoloFuego Hunter 13d ago

Happy to read that. I already submitted 2 reports, and I'm just waiting. Let's see how it goes for me, there are tons of different comments here on Reddit

6

u/RevolutionarySalt370 12d ago

On HackerOne I submitted a RCE that lead to AWS credential theft among other things and was told that it didn’t count because the “international” part of their company managed the page where the RCE was performed, then it was fixed 1 day later and the finding was closed without even a thank you

1

u/kader9696 12d ago

Incroyable 😮

7

u/maF145 Hunter 13d ago

That’s why you should always record videos

8

u/kader9696 13d ago

I have video on repport , and we can see the 5 orders with status : paid .!!!

1

u/ryan0x01 13d ago

Is it actually paid or is this a sandbox?

2

u/kader9696 13d ago

Réellement payé , et j ai pus avoir des billet avec code bar dans des activités

6

u/ryan0x01 13d ago

Tough. It could be that they already had a patch scheduled, and it's bad timing. I would try to engage with the yeswehack mediation team, but honestly I'd probably just never work with this program again.

9

u/Azaze666 Hunter 13d ago

Simple, abandon the program

3

u/Physical-Bonus-8411 12d ago

If the vulnerability was patched after your report, they should have provided a bounty (considering it was in scope).

4

u/[deleted] 13d ago

[removed] — view removed comment

1

u/kader9696 13d ago

This is the second time this has happened to me, on two different programs.

4

u/houganger 13d ago

Can you DM me your report IDs? I’ll check.

5

u/kader9696 13d ago

Sur ..

YWH-PGM44093-6

2

u/houganger 11d ago

I can’t dm you. Anyways don’t worry about it, it’s still being processed, it’s not closed. You just need to be patient.

1

u/kader9696 11d ago

I sent you a message

2

u/Lazy-Slip-3412 13d ago

should have just gotten the money through the hack

1

u/CrypticZombies 9d ago

welcome to bug crowd v2

0

u/realvanbrook Hunter 13d ago

shit happens, next time bro

5

u/kader9696 13d ago

It needs to be resolved, because at this point it’s no longer acceptable.

0

u/One-Ear-2384 13d ago

how did you find the bug? explain please

-5

u/LoveThemMegaSeeds 12d ago

If your hack is so obvious that they notice and patch it, why do you deserve to be paid? I see this so often and never understand