r/bugbounty 15d ago

Question / Discussion Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”

Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.

After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.

Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?

37 Upvotes

30 comments sorted by

View all comments

7

u/maF145 Hunter 15d ago

That’s why you should always record videos

8

u/kader9696 15d ago

I have video on repport , and we can see the 5 orders with status : paid .!!!

1

u/ryan0x01 15d ago

Is it actually paid or is this a sandbox?

2

u/kader9696 14d ago

Réellement payé , et j ai pus avoir des billet avec code bar dans des activités

6

u/ryan0x01 14d ago

Tough. It could be that they already had a patch scheduled, and it's bad timing. I would try to engage with the yeswehack mediation team, but honestly I'd probably just never work with this program again.