Email verification bypassed during sing up (████████)
Medium
M
MTN Group
Submitted None
Actions:
Reported by
ibrahimatix0x01
Vulnerability Details
Technical details and impact analysis
## Summary:
Normally ███ ask users to verify their email during registration but i found a way to bypass this so than an attacker can create accounts with emails that are not his own abusing the intigrity of MTN.
## Steps To Reproduce:
1. Create an account with you owned email, verify it.
1. Go ████ and change your email to the desired email you will not be asked to verify the ownership, in this case I changed mine to ```███████```.
1. Email verification bypassed successfully.
## Supporting Material/References:
## Impact
This issue can be used to bypass email verification on signup. Attackers can create account on behalf on any person without having access to the email account.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles