Improper authentication on registration

Disclosed: 2018-08-24 13:34:05 By lezibintlgent To semrush
Medium
Vulnerability Details
> Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. **Summary:** [one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. ] **Description:** [Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. ] ## Browsers Verified In: * [Google chrome] * [Mozilla] ## Steps To Reproduce: [reproduce steps] 1. [Register the email ID that does not exist] 2. [Click register button and then login to the account] 3. [Signout and again sign in using previous email ID] ## Supporting Material/References: [**Obligated field**] * Screenshots ) ## Impact Attacker can take benefit by using this weak access control and further login with the fake account that doesnot exit.
Actions
View on HackerOne
Report Stats
  • Report ID: 382667
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 5
Share this report