account-creation-vulnerability

1 article
sort: new top best
clear filter
0 5/10

A bug bounty finding demonstrating a 2FA bypass via forced browsing by directly accessing an unprotected signup endpoint (/_ajax/signup instead of /_api/signup/verify), allowing account creation without OTP verification by modifying the API request to include password field.

Akhil Burp Suite HackerOne Bugcrowd
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 14 hours ago · details