Remix.run Logo
voodooEntity 6 hours ago

Really nice finding for such a young folk - really liked reading into it.Also what i love most about it is what an actually simple vuln it is.

Tho what i find mostly funny bout it is how many people are complaining about the 4k$.

I mean sure the potential "damage" could have been alot higher, tho at the same time there was no contract in place or , at least as far as i understood, a clear bug bounty targeted. This was a, even if well done, random checking of XHR/Requests to see if anything vulnerable can be found - searching for kinda file exposure / xss / RFI/LFI. So everything paid (and especially since this is a mintlify bug not an actual discord bug) is just a nice net gain.

Also ill just drop here : ask yourself, are you searching for such vulns just for money or to make the net a safer place for everyone. Sure getting some bucks for the work is nice, but i personally just hope stuff gets fixed on report.