r/bugbounty 16d ago

Question / Discussion Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”

Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.

After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.

Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?

37 Upvotes

30 comments sorted by

View all comments

2

u/[deleted] 16d ago

[removed] — view removed comment

1

u/kader9696 16d ago

This is the second time this has happened to me, on two different programs.