Skip to main content

Command Palette

Search for a command to run...

Business Logic Flaw Allows Attackers to Block User Registrations via Email Invite Manipulation

Updated
1 min read
Business Logic Flaw Allows Attackers to Block User Registrations via Email Invite Manipulation
Z

Hi, I’m a bug bounty hunter and cybersecurity enthusiast who began my journey in 2023. I enjoy exploring and discovering hidden vulnerabilities in browsers, applications, and various platforms—especially those that are rarely examined by others. My focus is on browser and website security issues. I also share my findings and educational content through my YouTube channel, Lazy Cyber Security. https://8da993bf3fa4.ngrok-free.app

Penjelasan Singkat: Celah ini terjadi karena masalah pada penanganan database yang tidak tepat. Ketika undangan email dihapus, email tetap tersimpan dan dianggap “sudah terpakai”, meskipun target belum mendaftar. Hal ini menyebabkan pengguna baru tidak bisa mendaftar dengan email yang sama.

Cara Serangan:

  1. Penyerang mengundang email target.

  2. Penyerang menghapus undangan sebelum target mendaftar.

  3. Target mencoba mendaftar, tapi sistem menolak karena email sudah terpakai.

Kenapa Terjadi? Ini terjadi karena email yang sudah diundang tetap disimpan dalam database dan dianggap “terpakai” meski undangannya sudah dibatalkan.

More from this blog

B

BountyProofs | Bug Bounty Writeups & Free Tools

37 posts

Explore real-world bug bounty proofs of concept. Learn how ethical hackers find and exploit security flaws across platforms.