Loading HuntDB...

Email verification bypassed during sing up (████████)

Medium
M
MTN Group
Submitted None
Reported by ibrahimatix0x01

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
## Summary: Normally ███ ask users to verify their email during registration but i found a way to bypass this so than an attacker can create accounts with emails that are not his own abusing the intigrity of MTN. ## Steps To Reproduce: 1. Create an account with you owned email, verify it. 1. Go ████ and change your email to the desired email you will not be asked to verify the ownership, in this case I changed mine to ```███████```. 1. Email verification bypassed successfully. ## Supporting Material/References: ## Impact This issue can be used to bypass email verification on signup. Attackers can create account on behalf on any person without having access to the email account.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles