Bypass insecure password validation

Disclosed: 2017-11-16 08:08:29 By japz To infogram
Low
Vulnerability Details
Hi Team, ## Summary: Registration is checking the password creation __if the password is insecure__ , but the password reset page was not doing the same validation, so when i input an insecure password using the password reset, the validation on the password creation can be bypass because the password reset was not doing the same validation. ## Steps to reproduce: 1. Try to create/signup an account here: https://infogram.com/signup with password `1234567890` and the error message will appear: `Insecure password`. 2. Now lets bypass it, assuming i already created an account, now go to forgot password: https://infogram.com/forgot and enter you email. 3. The password reset link will send, click the link and it will redirect to password reset page. 4. On password reset, enter `1234567890` as your new password. 5. Password accepted! , insecure password validation has been bypassed. Let me know if you need more information. Regards Japz
Actions
View on HackerOne
Report Stats
  • Report ID: 287758
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report