Able to upload backgrounds before entering 2FA

Disclosed: 2021-02-03 14:37:30 By mr_vrush To cs_money
Medium
Vulnerability Details
## Summary: Hi Team, I am able to see and use uploaded backgrounds and able to upload new ones without proper authentication of 2FA. I hope you remember this report #993786. ## Steps To Reproduce: 1. Login with a steam account and enable 2FA. 1. Now logout your account. Clear all the cookies. 1. Now again login into your account now don't enter the 2FA code. 1. Go to the 3d.cs.money 1. If you are a Prime subscriber you are able to upload the custom backgrounds by pressing the "ctrl+v" combination. If you have already uploaded some backgrounds you are able to see those too. ## Supporting Material/References: Please check the attachment F1162263. ## Impact Able to access subdomain without proper authentication. It should be accessible after the proper authentication. Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 1080839
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report