Hacker News new | ask | show | jobs
by XCSme 1619 days ago
It's a nice find, but I still fail to see how it is a vulnerability or a security issue.
1 comments

I posted a case to HackerOne with the intent to warn against this behavior and with the weakness type "Business Logic Errors". Please, read in my report section "Impact" and my answer about the potentional impact of the reported behavior.

But, as maxltv clarified, it's not a policing tool but an authoring tool and described use of the product violate their TOS. My case is relevant if clients use it as a policing tool.

We continued our discussion in this thread https://news.ycombinator.com/item?id=29933516#29947146