Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: dm any people without being friends with #104

Open
1 task done
Neqkoo opened this issue Nov 25, 2024 · 2 comments
Open
1 task done

[Bug]: dm any people without being friends with #104

Neqkoo opened this issue Nov 25, 2024 · 2 comments
Labels
approved The topic is approved by a developer bug Something isn't working

Comments

@Neqkoo
Copy link

Neqkoo commented Nov 25, 2024

Checked Existing

  • I have checked the repository for duplicate issues.

What happened?

Recently, I found out a bug on the juxt website where you can dm people a blank message without being friends with, by simply going to a random dm, go to the post container, and then changing the pid of the person that you're messaging with to another person pid

I don't know and not sure if this works all the time, and if it can be abusable or not

What did you expect to happen?

I sometimes mess around to find any bugs to report them, I expected this one to fail, but it did not

Steps to reproduce?

[https://www.youtube.com/watch?v=bawTY0sHypA](url)

Other relevant information. (OPTIONAL)

No response

@Neqkoo Neqkoo added awaiting-approval Topic has not been approved or denied bug Something isn't working labels Nov 25, 2024
@jonbarrow
Copy link
Member

For exploits like this please use the appropriate channels. We have an actual dedicated section for exploits. Things like this should not be report as public bugs, please use https://github.com/PretendoNetwork/juxtaposition-ui/security/advisories/new

@ExperiencersInternational
Copy link

ExperiencersInternational commented Nov 25, 2024

For exploits like this please use the appropriate channels. We have an actual dedicated section for exploits. Things like this should not be report as public bugs, please use https://github.com/PretendoNetwork/juxtaposition-ui/security/advisories/new

It's not the OP's fault here, they originally posted this on Discord support and I advised them to report it on the GitHub as a bug since I didn't feel like it was a vulnerability (but I was clearly mistaken, can send you the original thread if you want).

Can confirm that we privately tested this though

@CaramelKat CaramelKat added approved The topic is approved by a developer and removed awaiting-approval Topic has not been approved or denied labels Jan 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved The topic is approved by a developer bug Something isn't working
Projects
Status: No status
Development

No branches or pull requests

4 participants