Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account

Publishing my first Security Vulnerability report for LinkedIn.

Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account

Below is the report that I have submitted to LinkedIn Information Security Team.

---Begin Report---

Reported Issues

1. Reporting a flaw in LinkedIn connections, Bypassing Weekly limits in Basic (free) Account

Brief

LinkedIn user(with Free Basic Plan) was able to connect to unlimited users even after exceeding the "Weekly Limit". There is a limit in how many people you can connect to in a week. After reaching the limit popup saying "you have reached your weekly limit" displays. If you go to responsive mode (normally in a browser by right mouse button and click "inspect"). After refreshing the page it goes to responsive mode. In this version, you can send "connection" requests to people even after you reached the limit.
The impact was, basic users, can bypass the weekly limit. Since this was a known issue, fixed by the LinkedIn team.

Reproduction Steps: Use a web browser and open LinkedIn in responsive mode (for web lite version). Stepwise as shown in following images
Browser used: Brave Browser, Chrome
OS: win 10,win 11
Linkedin : Web application
Severity: Medium

conncet after reaching weekly limit reached weekly limit inspect page for responsive mode refreh conncet now invitation successful

Timeline

DateReportSecurity Team's ResponseStatus
2021-07-26Reproduction stepsRequire Additional Info-
2021-07-27PoC Video and detail stepsKnown Issue, working on fixKnown-Issue
2021-07-29Disclosure policies, Reported new BUG (in 2)Disclosure after the issue is fixed and Team approvalFixing, Undisclosed
2021-09-2Issue persist even after fixRecheckingFixed, Undisclosed
2022-02-11DraftNo objection to publishdisclosed
2022-02-15--Published
--- End of Issue 1 ---

2. The issue regarding the ability to connect to 3rd degree + connections

Brief

In this issue, the user was able to connect to the 3+ (Third plus) degree connections. These are different levels of connections in LinkedIn. 3+ are the people which are out of your network. Normally the name is displayed as a placeholder "LinkedIn Member". These are higher than 3rd-degree connections. In a basic free plan, a user is not allowed to connect to them, Not even see their name or profile detail(can only see their position and company). With this info(position and company name), you can find out their name and profile by doing the same reproduction steps as issue 1 but with no connection to issue 1 at all. User can see their name and their profile, activity, etc which is not possible normally. This issue exposes the information(Name, profile details, activities)of the users to the outside networks and you are able to connect to them.
This issue was reported and and was not previously known, later verifierd and acknowlwdged by LinkedIn Security team and currently tested and fixed.

Reproduction Steps: Use a web browser and open LinkedIn in responsive mode (for web lite version). Stepwise as shown in following images
Browser used: Brave Browser, Chrome
OS: win 10,win 11
Linkedin : Web application
Impact: Medium
Information Security (User data, activity and privecy(via conncetion/message)): Medium

find people who are out of your network copy positions or any identyfying info profile access not possible inspect page for responsive refresh page paste info as copied earlier tada ! the profile is now accessible connect request invitation send

Timeline

DateReportSecurity Team's ResponseStatus
2021-07-29Issue report,3rd+ degree connection--
2021-09-14-Require Additional Info, PoC-
2021-09-21Sent PoC videoAcknowledgementInvestigating(2021-10-19)
2021-11-2-UpdateConfirmed Issue
2021-11-17Test fixed issueupdated as fixedFixing
2021-11-18retest,reported as still not fixedAcknowledgementIssue persist
2021-12-20test and confirmedupdated as fixedFixed, Undisclosed
2022-02-11DraftNo objection to publishdisclosed
2022-02-15--Published
---End of Issue 2---
---End of Report---

P.S.: I am new to both blogging and bug bounty. I may update the content(not the actual report, but the motivation, Drafts and report timeline, HackerOne's Bounty programs, any related queries hereafter, etc. ) of this blog.