Should I report a bug to a federal(-ish) university without hopes of a bug bounty?
I live in nigeria,
I attend national open university of nigeria. I recently found out a bug which allowed me to register all my courses without payment(I.E Basically attend the university for free), change stuff like number of credit units(which allows me to take on infinite courses, register courses I shouldn't have access to and stuff like that. There is prolly more (given their terribly designed api) but I didn't look further.
I'm wandering whether I should report the bug since I dont know if I have hopes of a bug bounty. P.S I really need money rn so looking for any way to get some.
1 Reply
be a virtuous person and report it to them regardless of the perceived chances of getting a bounty :poohheh: