email-verification-bypass

3 articles
sort: new top best
clear filter
0 5/10

A bug bounty finding demonstrating a 2FA bypass via forced browsing by directly accessing an unprotected signup endpoint (/_ajax/signup instead of /_api/signup/verify), allowing account creation without OTP verification by modifying the API request to include password field.

Akhil Burp Suite HackerOne Bugcrowd
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 12 hours ago · details
0 6/10

A researcher escalated a P5 email verification race condition vulnerability to a P2 blind XSS by chaining it with a profile display feature that revealed unverified emails to administrators, ultimately achieving session hijacking and a $1000+ bounty.

Mohamed Daher Bugcrowd xsshunter.com Burp
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details
0 2/10

A writeup about the author's first bug bounty finding involving an email verification bypass, but the provided excerpt contains no technical details, methodology, or substantive content.

medium.com · Ankit Rathva aka Gujarati Hacker · 22 hours ago · details