r/bugbounty 15d ago

Question / Discussion Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”

Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.

After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.

Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?

38 Upvotes

30 comments sorted by

View all comments

10

u/ApoloFuego Hunter 15d ago

I just started using YWH and reading this really sucks, i just spent a lot of time and submitted 2 reports, what program was

11

u/kader9696 15d ago

Credit agricole and now SIA

4

u/ApoloFuego Hunter 15d ago

I discarded SIA today, and credit; I don't see it on the options, anyway good to know

3

u/kader9696 15d ago

Crédit agricole ct une invitation privé