Loading HuntDB...

Signup with any email and enable 2FA without verifying email

Medium
O
Omise
Submitted None
Reported by rioncool22

Vulnerability Details

Technical details and impact analysis

##Description : When i signup, i can enable 2FA without verification my email. ##Attack Scenario : 1. The Attacker signup with the victim email. 2. Go to `Two factor authetication` and enable 2FA ## Impact when the victim want to register in this [site](https://dashboard.omise.co/), they can't, because they email claims by attacker. and if the victim reset the password to get back the email, he can, but he can't login because need 2FA code.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted