Loading HuntDB...

Bypass insecure password validation

Low
I
Infogram
Submitted None
Reported by japz

Vulnerability Details

Technical details and impact analysis

Hi Team, ## Summary: Registration is checking the password creation __if the password is insecure__ , but the password reset page was not doing the same validation, so when i input an insecure password using the password reset, the validation on the password creation can be bypass because the password reset was not doing the same validation. ## Steps to reproduce: 1. Try to create/signup an account here: https://infogram.com/signup with password `1234567890` and the error message will appear: `Insecure password`. 2. Now lets bypass it, assuming i already created an account, now go to forgot password: https://infogram.com/forgot and enter you email. 3. The password reset link will send, click the link and it will redirect to password reset page. 4. On password reset, enter `1234567890` as your new password. 5. Password accepted! , insecure password validation has been bypassed. Let me know if you need more information. Regards Japz

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted