#(Not sure) Juxt Website vulnerability report

1 messages · Page 1 of 1 (latest)

magic moth
#

Recently, I found out a vulnerability on the juxt website where you can dm people a blank message without being friends with

I don't know and not sure if this works all the time, and if it can be abusable or not

I have a video of me showing how it works, should I send it here?

#

(I think) With this, you can even dm people like Jon using this vulnerability

fast locust
#

i will let jon know to make everything free

#

😡

tranquil star
#

I wouldn't class this as a vulnerability, it's just a bug.

Please file this in the appropriate GitHub repository instead of here

sudden lagoon
#

And make sure they are actually exploitable first

#

And how much damage it can cause

magic moth
sudden lagoon
#

Spamming random people's inbox is not actually a minor issue

#

If it works it's actually very serious

#

And you dont want bad actors reading this thread and starting causing chaos

fast locust
tranquil star
#

@sudden lagoon might be worth closing the thread, I took this a bit less seriously than it should be taken

tranquil star
sudden lagoon
magic moth
#

Yeah might be worth closing the thread

sudden lagoon
#

and then report it on github