SignUp using Fake Email
Unknown
Vulnerability Details
In this trial I used the email '[email protected]' and after pressing the SIGN UP button it will automatically redirect to https://ppp.woelkli.com/apps/preferred_providers/password/set/emailfakeforregister/H2qlEWHxQ3yiJgCsEXkR8, not through the account verification process first.
For full the link PoC can see on the link this: https://drive.google.com/file/d/1VX5MBh7WR__Zj2lIup4TtS81VawPy0F7/view?usp=drivesdk
Thank you.
## Impact
This will enable someone to create multiple accounts at once without verification.
Actions
View on HackerOneReport Stats
- Report ID: 664200
- State: Closed
- Substate: informative
- Upvotes: 3