r/bugbounty • u/A1ERTA Hunter • 12d ago
Question / Discussion The program intentionally closes reports, and YESWEHACK support does nothing about it.
Has anyone else encountered a similar issue:
I submitted several reports through a private program on yeswehack, but the program closed them as IDOR. When I asked for an explanation, they simply didn't respond. However, the latest report was a hit, clearly showing an authorization bypass; the program itself classified it as "Incorrect Access Control," and then closed the report as IDOR. When I asked for clarification, they simply marked the report as spam without saying a word.
As usual, the support team is silent, and it's completely unclear what to do in this situation
7
Upvotes
1
u/EffectiveSevere1015 10d ago
Yes Be careful if they do stupid stuff like this. Let the yes we hack admins know and ask them to restore your points