Able to upload backgrounds before entering 2FA
Medium
C
CS Money
Submitted None
Actions:
Reported by
mr_vrush
Vulnerability Details
Technical details and impact analysis
## Summary:
Hi Team,
I am able to see and use uploaded backgrounds and able to upload new ones without proper authentication of 2FA. I hope you remember this report #993786.
## Steps To Reproduce:
1. Login with a steam account and enable 2FA.
1. Now logout your account. Clear all the cookies.
1. Now again login into your account now don't enter the 2FA code.
1. Go to the 3d.cs.money
1. If you are a Prime subscriber you are able to upload the custom backgrounds by pressing the "ctrl+v" combination. If you have already uploaded some backgrounds you are able to see those too.
## Supporting Material/References:
Please check the attachment F1162263.
## Impact
Able to access subdomain without proper authentication.
It should be accessible after the proper authentication.
Thanks
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Authentication - Generic