Scam Alert: iproyal.com — Bug Bounty time travel
Company / Program: iproyal.com
Platform: Self-Hosted · Severity: medium · Scam type: false-dup
Published:
Reported by: abhirup konwar
A security researcher reported a privilege escalation vulnerability in April that allowed a user to escalate privileges from Admin to Owner. The report was acknowledged and remained under review.
Months later, the researcher received a surprising response: the report was marked as a duplicate of another report that had allegedly been submitted in June.
Yes, June.
Apparently, in this bug bounty program, reports submitted in the future can become the original report, while earlier reports become duplicates.
Either the laws of time have changed, or someone forgot to check the submission dates before closing the report.
Researchers expect fair triage, transparent communication, and consistent decision-making. Marking an April submission as a duplicate of a June submission raises serious questions about the review process and whether reports are being handled with proper attention.
Maybe the real bug wasn't the privilege escalation.
Maybe the real bug was in the timeline.