▲ 9 r/bugbounty
I found some bugs, need help!
I am doing bug bounty on a target from bugcrowd, and found some interetsing IDOR PII leaks
the bug remains same but on 4-5 different endpoints/parameter
for example
/api/user/smth/smth?q=EMAIL
/api/v2/user/smth/smth?q=EMAIL
/api/user/smth/smth?uuid=UUID
/api/v2/user/smth/smth?uuid=UUID
/api/user/smth/UUID
All of them leaks the same PII
Should i report every endpoint as individual or combine all of them in 1 report
u/Impressive-Room728 — 2 days ago