Weak rate limit for SIGN.PLUS email verification
Low
A
Alohi
Submitted None
Team Summary
Official summary from Alohi
zeesozee identified a way to reset the rate limit concerning the "Confirm your email" verification endpoint for new accounts. This increases the chance of successful bruteforce from an attacker who would try to register with a fake email. The issue was fixed immediately.
Actions:
Reported by
zeesozee
Report Details
Additional information and metadata
State
Closed
Substate
Resolved