Vine - overwrite account associated with email via android application

Disclosed: 2017-06-14 23:35:01 By mishre To x
Medium
Vulnerability Details
Hi, It's possible to deny any user from logging in to his account by overwriting the password associated with his email. This is not an account takeover because while we do override the password associated with that specific mail we just login to a "new" account and not the user's original one. Steps to reproduce: === 1) Create first account via Vine for android with the mail [email protected] with the password Bla123 2) You can now see that you can login to the account created above. 3) Go and create another account - this time with a different password and with the mail [email protected] - notice the CAPS (you can put the caps everywhere on the mail). 4) Finish the creation process - and see that it succeeds 5) Now go back and try to login with [email protected] and the password Bla123 and see that you can't. However, it's possible to login with [email protected] and the second password you have created - but you"ll login to the second created account.
Actions
View on HackerOne
Report Stats
  • Report ID: 187714
  • State: Closed
  • Substate: resolved
  • Upvotes: 24
Share this report