Loading HuntDB...

Weak Password Policy on Signup at https://accounts.bistudio.com/auth

B
BOHEMIA INTERACTIVE a.s.
Submitted None
Reported by hack2684

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Hi, I found that you are using a weak password policy! Because user can set his password same as Email address! Steps To reproduce: 1. Register an account with Email address "[email protected]" 2. Also password "[email protected]". You can see both values are same. You will become successfully register with these information which can easily guessable by anyone. Kindly restrict user that password should be same as Email address! Thanks, ## Impact Password should not match with Email address because if password is same as Email address then account can be compromise easily!

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Violation of Secure Design Principles