Create New User Whilst Logged On
None
S
Starbucks
Submitted None
Actions:
Reported by
id-is-vulnerable
Vulnerability Details
Technical details and impact analysis
The website www.teavana.com allows users already logged on to create new account with a very simple url redirect. When an account is created a page is displayed with your account information and what you want to update. By simply refreshing the page allows you to create a new account whilst still logged on. If you try to recreate the same account with the same email but different password, there will be no error message displayed though when you try to login, the password will be incorrect.
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Open Redirect