Loading HuntDB...

Weak rate limit for SIGN.PLUS email verification

Low
A
Alohi
Submitted None

Team Summary

Official summary from Alohi

zeesozee identified a way to reset the rate limit concerning the "Confirm your email" verification endpoint for new accounts. This increases the chance of successful bruteforce from an attacker who would try to register with a fake email. The issue was fixed immediately.

Reported by zeesozee

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted