Signup with any email and enable 2FA without verifying email
Medium
O
Omise
Submitted None
Actions:
Reported by
rioncool22
Vulnerability Details
Technical details and impact analysis
##Description :
When i signup, i can enable 2FA without verification my email.
##Attack Scenario :
1. The Attacker signup with the victim email.
2. Go to `Two factor authetication` and enable 2FA
## Impact
when the victim want to register in this [site](https://dashboard.omise.co/), they can't, because they email claims by attacker.
and if the victim reset the password to get back the email, he can, but he can't login because need 2FA code.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved