possibility to create account without username
Medium
I
Infogram
Submitted None
Actions:
Reported by
luthrax
Vulnerability Details
Technical details and impact analysis
hi ,
infogram.com doesn't allow us to go next untill we give name of our account but i bypassed that. i am able to create an account without any name, just by modify response field.
#steps:-
1. create new account , when you reach page where you have to give your name.
2. give name and intercept the request , remove first name and last name and forward the request.
3. now you will get reponse with 400 bad gateway , you just need to remove it and modify with 200 and forward it , your account will be created.
here is the video poc how to create account without any name
{F357158}
regards
## Impact
bypass "name giving to account field to complete signup"
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles