Bypass insecure password validation
Low
I
Infogram
Submitted None
Actions:
Reported by
japz
Vulnerability Details
Technical details and impact analysis
Hi Team,
## Summary:
Registration is checking the password creation __if the password is insecure__ , but the password reset page was not doing the same validation, so when i input an insecure password using the password reset, the validation on the password creation can be bypass because the password reset was not doing the same validation.
## Steps to reproduce:
1. Try to create/signup an account here: https://infogram.com/signup with password `1234567890` and the error message will appear: `Insecure password`.
2. Now lets bypass it, assuming i already created an account, now go to forgot password: https://infogram.com/forgot and enter you email.
3. The password reset link will send, click the link and it will redirect to password reset page.
4. On password reset, enter `1234567890` as your new password.
5. Password accepted! , insecure password validation has been bypassed.
Let me know if you need more information.
Regards
Japz
Report Details
Additional information and metadata
State
Closed
Substate
Resolved