-
Notifications
You must be signed in to change notification settings - Fork 795
Open
Description
Weakness: Violation of Secure Design Principles
Severity: Medium
Vulnerable Host: steemit.com
Summary:
I was able to Bypass the 2FA verification code through bruteforcing the code.Thus, It could be misused by an attacker to misuse other emails of your customers/users and bruteforce the verification code.
Video POC:
https://drive.google.com/file/d/1qxHfRTh0kAq0bkSsx2wVDVB3-8ze-nC8/view?usp=sharing
Impact:
Emails can be misused and the email verification code can be bypassed.
Looking forward to hear from you soon and to report further.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels