Exploits / Vulnerability Discovered : 2022-09-20 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Bookwyrm v0.4.3 authentication bypass is for educational purposes only and if it is used you will do on your own risk!
Description: Email Verification Bypass Leads To Account Takeover in bookwyrm-social/bookwyrm v0.4.3 Due To Lack Of Ratelimit Protection
# Steps to reproduce:
1. Create a acount with victims email id
2. When the account is created, its ask for email confirmation via validating OTP
Endpoint: https://site/confirm-email
3. Enter any random OTP and try to perfrom bruteforce attack and if otp matches, We can takeover that account