Loading HuntDB...

Able to upload backgrounds before entering 2FA

Medium
C
CS Money
Submitted None
Reported by mr_vrush

Vulnerability Details

Technical details and impact analysis

Improper Authentication - Generic
## Summary: Hi Team, I am able to see and use uploaded backgrounds and able to upload new ones without proper authentication of 2FA. I hope you remember this report #993786. ## Steps To Reproduce: 1. Login with a steam account and enable 2FA. 1. Now logout your account. Clear all the cookies. 1. Now again login into your account now don't enter the 2FA code. 1. Go to the 3d.cs.money 1. If you are a Prime subscriber you are able to upload the custom backgrounds by pressing the "ctrl+v" combination. If you have already uploaded some backgrounds you are able to see those too. ## Supporting Material/References: Please check the attachment F1162263. ## Impact Able to access subdomain without proper authentication. It should be accessible after the proper authentication. Thanks

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Improper Authentication - Generic