Question Time

Questions or suggestions about the platform
Post Reply
c0rtePentest
Posts:38
Joined:Fri Oct 07, 2016 8:21 pm
Contact:
Question Time

Post by c0rtePentest » Wed Oct 18, 2017 3:22 pm

Hi community.

I have some questions because sometimes I don't know if i should report a vulnerability in openbugbounty.

Example:

I find a XSS vulnerability in big website. I make a search if anyone has already reported and i see something like 15 reports
12 unpatched and 3 resolved. Should I report anyway?
And if the site has 10 reports and 10 unpatched?

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Question Time

Post by secuninja » Wed Oct 18, 2017 9:34 pm

u need to check if one of the unpatched is a duplicate to yours. if so, clone reports are not accepted.
if you fonund a duplicate on an already patched vuln, create report. either it was patched and is vulnerable again or it was never patched and marked so for whatever reason.

if u create the report anyway without checking it probably will be declined as clone.

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests