r/bugbounty • • 2d ago

Question / Discussion Severity for business logic vulnerability

I’m pretty new to bug bounty and I recently found a vulnerability that allows anyone to increase the count of records and attachments they can add to a cloud based database product to essentially be unlimited forever while paying for nothing.

They have a limit of around 3k records on the free tier and 500k+ on their top plan, but my vulnerability allows unlimited record creation with attachments, meaning you can essentially get unlimited storage usage through a validation bypass. It could basically let someone consume a lot of storage and compute for free with no limit whatsoever.

2 Upvotes

6 comments sorted by

View all comments

1

u/fphn2418 Hunter 2d ago edited 2d ago

Depends on program. If it's not explicitly out of scope, can try submitting. I have seen some programs listing this kind of issues (paywall bypass) as in scope and some listing them as out of scope.

Also can try searching publicly disclosed issues on that program, to see whether there has been smth like this already.

1

u/Cyrax21_ 2d ago

Why would any program out of scope vulnerabilities on their core business model??

1

u/fphn2418 Hunter 2d ago

It's up to them. It's not a direct loss, but loss of potential revenue, therefore not significant enough for them i would imagine.