Password Policy issue
Unknown
Vulnerability Details
Hello
I hope you are doing fine. This is a very low severity issue that i just found out in your password policy. You have a good password policy implemented with the special characters and uppercase letters and stuff but the thing is that you do not check for passwords similar to the other fields. Like if someone has put their email as same as their password or their username or real name as same as their password, there is no check for this. Which leaves the account vulnerable to guessing attacks because we of all the world know that the attacker initially goes for the similarities.
You could reproduce this by signing up for an account that has real name that is same the email address that is as username that is as same as the password (ignoring the @ and the . in the email offcourse because that is not accepted). This should be checked
Hope this helps. Awaiting your reply
Actions
View on HackerOneReport Stats
- Report ID: 26758
- State: Closed
- Substate: informative
- Upvotes: 2