SignUp using Fake Email

Disclosed: 2019-08-02 08:29:13 By j4tayu To nextcloud
Unknown
Vulnerability Details
In this trial I used the email '[email protected]' and after pressing the SIGN UP button it will automatically redirect to https://ppp.woelkli.com/apps/preferred_providers/password/set/emailfakeforregister/H2qlEWHxQ3yiJgCsEXkR8, not through the account verification process first. For full the link PoC can see on the link this: https://drive.google.com/file/d/1VX5MBh7WR__Zj2lIup4TtS81VawPy0F7/view?usp=drivesdk Thank you. ## Impact This will enable someone to create multiple accounts at once without verification.
Actions
View on HackerOne
Report Stats
  • Report ID: 664200
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report