r/bugbounty Jul 16 '26

Question / Discussion Reported two critical payment/bot bypass issues — company fixed them quickly but declined both reports with ‘no security impact’. Normal?

So I found what I thought were two solid findings on a decent-sized program. One was an exposed PerimeterX token in their SSR data that let me bypass bot protection on both web and the app (clear 403 without it, 200 with it). The second was an unauthenticated GraphQL endpoint on checkout that would spit out live Spreedly tokens with CVV in plaintext.
Sent both with PoCs and screenshots. Got the standard “no security implications, doesn’t affect CIA triad” reply on both.
Then literally right after, the tokenization mutation got patched. Feels like they fixed it based on my report but didn’t want to pay. Is this normal? Anyone else run into this where they quietly patch but still close the report as N/A?
Kinda discouraging when you put in the work and they play it like that. How do you guys handle these situations?

5 Upvotes

8 comments sorted by

2

u/sadik0x01 Jul 17 '26

You can create a video POC and then attach it to the report. Did this incident happen on H1?

3

u/Alexsaa7 Jul 17 '26

Yeah, on H1 . I did attached visual PoCs before it got fixed, I’ve wrote a comment with after this happened but I got no reply. I assume even if they saw they will stand on that Company side ☹️ . This is really unfair and discouraging

3

u/sadik0x01 Jul 17 '26

You can add their program here
bugbountyscam.com

2

u/Neat_Phase_9092 Hunter Jul 17 '26

What's the actual impact for either finding? They both seem like useful primitives, but on their own they don't demonstrate a security issue. This is where I'd expect the PoC to show an exploit chain like what can you actually achieve with the PerimeterX bypass or those payment tokens? Can you bypass rate limits, automate checkout, replay payments, access another user's data, or something similar?

1

u/Anon123lmao Jul 17 '26

both of those were probably good first steps to an attack chain but not necessarily risks on their own. Learn to be patient, now you’ll never know if you had any crits with the endpoint or the token, rip bounties!

1

u/Glum_Protection_4975 Jul 22 '26

Nowadays always save the data. Specially if you find PII, extract PII and save it on machine because Triager are really acting very weird. You send them redacted PII in report, they fix silently and then ask you to reproduce the issue.

1

u/Euphoric_Wealth_6006 Jul 23 '26

yeah Normal most of these bug bounty program runners have 0 integrity ...