Able to upload backgrounds before entering 2FA
Medium
Vulnerability Details
## Summary:
Hi Team,
I am able to see and use uploaded backgrounds and able to upload new ones without proper authentication of 2FA. I hope you remember this report #993786.
## Steps To Reproduce:
1. Login with a steam account and enable 2FA.
1. Now logout your account. Clear all the cookies.
1. Now again login into your account now don't enter the 2FA code.
1. Go to the 3d.cs.money
1. If you are a Prime subscriber you are able to upload the custom backgrounds by pressing the "ctrl+v" combination. If you have already uploaded some backgrounds you are able to see those too.
## Supporting Material/References:
Please check the attachment F1162263.
## Impact
Able to access subdomain without proper authentication.
It should be accessible after the proper authentication.
Thanks
Actions
View on HackerOneReport Stats
- Report ID: 1080839
- State: Closed
- Substate: informative
- Upvotes: 3