Improper authentication on registration
Medium
S
Semrush
Submitted None
Actions:
Reported by
lezibintlgent
Vulnerability Details
Technical details and impact analysis
> Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform.
**Summary:**
[one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform.
]
**Description:**
[Hope you are doing well, one can register himself to semrush with any email ID. It means that there is no authentication mechanism if that email id is valid/invalid. Therefore a person with email ID that does not exist can also register and login to your platform.
]
## Browsers Verified In:
* [Google chrome]
* [Mozilla]
## Steps To Reproduce:
[reproduce steps]
1. [Register the email ID that does not exist]
2. [Click register button and then login to the account]
3. [Signout and again sign in using previous email ID]
## Supporting Material/References:
[**Obligated field**]
* Screenshots
)
## Impact
Attacker can take benefit by using this weak access control and further login with the fake account that doesnot exit.
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Improper Authentication - Generic