Email verification bypassed during sing up (████████)
Medium
Vulnerability Details
## Summary:
Normally ███ ask users to verify their email during registration but i found a way to bypass this so than an attacker can create accounts with emails that are not his own abusing the intigrity of MTN.
## Steps To Reproduce:
1. Create an account with you owned email, verify it.
1. Go ████ and change your email to the desired email you will not be asked to verify the ownership, in this case I changed mine to ```███████```.
1. Email verification bypassed successfully.
## Supporting Material/References:
## Impact
This issue can be used to bypass email verification on signup. Attackers can create account on behalf on any person without having access to the email account.
Actions
View on HackerOneReport Stats
- Report ID: 1182016
- State: Closed
- Substate: resolved
- Upvotes: 17