Captcha Bypass in Coinbase SignUp Form
Low
C
Coinbase
Submitted None
Actions:
Reported by
tejpratap
Vulnerability Details
Technical details and impact analysis
Vulnerability description:
The g-recaptcha-response is not validated on the server-side when submitting a Signup form to the endpoint. Any or no value can be provided for this header
Step to reproduce:
1. https://www.coinbase.com/signup
2. Fill the input field and Validate the captcha.
3. Trun on Brurp submit form and capture the request.
4. Remove the g-recaptcha-response( response value) and foreword it.
Impact.
Fake accounts can be created. Also username enumeration can be performed because no application will allow two email to choose same email.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$100.00
Submitted
Weakness
Violation of Secure Design Principles