▲ 32 r/bugbounty
Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”
Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.
After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.
Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?
u/kader9696 — 3 days ago