HackenProof Disclosed Report

Bug bounty report HackenProof

Account Enumeration via Reuse of Email Addresses

Created date
Mar 15 2023

Target

Main website

Vulnerability Details

The vulnerability i mentioned, which is allowing users to create multiple accounts with a single email address by just intercepting the request and putting a space at the begining of the email, this type of broken authentication vulnerability can have serious security implications for a system, this could allow an attacker to create multiple accounts using a single email address, allowing them to impersonate other users

Validation steps

  1. create(sign-up) for an account.
  2. complete verification via email
  3. Go ahead and try signing up with the same email address, add a space using burp Suite
  4. You will then recieve an email address to confirm or activate your account after previous doing so, but this time with different user name and pass

Attachments

hidden
CommentsReport History
Comments on this report are hidden
Details
Statedisclosed
Severity
Medium
Bounty$0
Visibilitypartially
VulnerabilityBroken Authentication and Session Management
Participants (2)
company admin
author