Loading HuntDB...

possibility to create account without username

Medium
I
Infogram
Submitted None
Reported by luthrax

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
hi , infogram.com doesn't allow us to go next untill we give name of our account but i bypassed that. i am able to create an account without any name, just by modify response field. #steps:- 1. create new account , when you reach page where you have to give your name. 2. give name and intercept the request , remove first name and last name and forward the request. 3. now you will get reponse with 400 bad gateway , you just need to remove it and modify with 200 and forward it , your account will be created. here is the video poc how to create account without any name {F357158} regards ## Impact bypass "name giving to account field to complete signup"

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles