Loading HuntDB...

Improper authentication on registration

Medium
S
Semrush
Submitted None
Reported by lezibintlgent

Vulnerability Details

Technical details and impact analysis

Improper Authentication - Generic
> Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. **Summary:** [one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. ] **Description:** [Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform. ] ## Browsers Verified In: * [Google chrome] * [Mozilla] ## Steps To Reproduce: [reproduce steps] 1. [Register the email ID that does not exist] 2. [Click register button and then login to the account] 3. [Signout and again sign in using previous email ID] ## Supporting Material/References: [**Obligated field**] * Screenshots ) ## Impact Attacker can take benefit by using this weak access control and further login with the fake account that doesnot exit.

Report Details

Additional information and metadata

State

Closed

Substate

Not-Applicable

Submitted

Weakness

Improper Authentication - Generic