Email Verification Bypass using Race Condtion

Disclosed by
arthbajpai277
  • Engagement Pinterest
  • Disclosed date almost 5 years ago
  • Points 5
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by arthbajpai277

We found Out a vulnerability in their email verification process and was able to bypass it and turn on 2fa(Step After Email verification), this vulnerability started as Race condition where user had to send a bugged request to server multiple times in a short amount of time to make this work, but Later We found that it works by sending Just Single time as well

Thanks to Wilson sir and Pinterest team

Regards
Arth Bajpai

Activity