You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
An attacker can create a Runbox account using the victim’s email. Even without email verification, the attacker can log in and enable OTP, locking the victim out permanently.
To Reproduce
Steps to reproduce the behavior:
Create a runbox account using the victim's email
A verification mail will be sent to victim's email
Victim won't notice that and thus don't verify the mail.
As an attacker, go to login page and try to login with the username and password of the account you created a while ago
You will see that login is successful
Now go to account security and generate and enable OTP from there
Victim's account takeover successful. Victim won't be able to access his account any more
Expected behavior
Login shouldn't be possible without email verification. Also OTP generation or enable shouldn't be possible without email verification of a user
Describe the bug
An attacker can create a Runbox account using the victim’s email. Even without email verification, the attacker can log in and enable OTP, locking the victim out permanently.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Login shouldn't be possible without email verification. Also OTP generation or enable shouldn't be possible without email verification of a user
Severity
High (P1)
** PoC Video Link **
https://drive.google.com/file/d/11o0yaLyOH93v3Kx7Fe26freSPzHOpCXM/view?usp=sharing
The text was updated successfully, but these errors were encountered: