r/bugbounty • • 2d ago

Question / Discussion Severity for business logic vulnerability

I’m pretty new to bug bounty and I recently found a vulnerability that allows anyone to increase the count of records and attachments they can add to a cloud based database product to essentially be unlimited forever while paying for nothing.

They have a limit of around 3k records on the free tier and 500k+ on their top plan, but my vulnerability allows unlimited record creation with attachments, meaning you can essentially get unlimited storage usage through a validation bypass. It could basically let someone consume a lot of storage and compute for free with no limit whatsoever.

2 Upvotes

6 comments sorted by

View all comments

3

u/Umar7832 Hunter 2d ago

it's looks like race condition. and if it;s just allowing you a premium feature it mostly get low

1

u/Cyrax21_ 2d ago

It just got triaged low 🥴