Bypassing Recaptcha Protection in `https://connect.acronis.com`
Low
Vulnerability Details
The Recaptcha Token is not validated in `https://connect.acronis.com/auth/register`
The Invader can reuse the same Token to create infinite other user accounts, and flood the system.
{F1847755}
{F1847756}
##Suggested Mitigation/Remediation Actions:
1. Limiting the request to once every X minutes.
2. Make sure that every request is checked for correct recaptchaand is then processed.
## Impact
The whole purpose of having the security feature of captcha has gone in vain.
##Possible Scenarios:
1. Attacker could use this vulnerability to bomb out the system.
2. Attacker might cause denial of service to servers.
Actions
View on HackerOneReport Stats
- Report ID: 1655629
- State: Closed
- Substate: resolved
- Upvotes: 25