- Status Closed
-
Assigned To
cbay - Private
Opened by monty099 - 31.07.2024
Last edited by cbay - 31.07.2024
FS#66 - *Title:* Insufficient Validation Allows Multiple Accounts Creation Under Single Subscription Plan
*Title:* Insufficient Validation Allows Multiple Accounts Creation Under Single Subscription Plan
*Description:*
A vulnerability has been identified in the subscription management system which allows users to create multiple accounts under the same subscription plan. This issue can be exploited to bypass restrictions on the number of accounts per plan and gain unauthorized benefits.
*Steps to Reproduce:*
1. *Create an Account:*
- Sign up for a new account with a specific subscription plan (e.g., "Free Plan").
2. *Create a Duplicate Account:*
- Attempt to create another account using the same subscription plan as the first account.
- Notice that the system does not prevent the creation of multiple accounts under the same subscription plan.
3. *Create a Similar Plan Account:*
- From the newly created account, sign up for a subscription plan similar to the first account's plan.
4. *Send an Invitation:*
- Send an invitation from the second account to the first account to become an admin of the plan created by the second account.
5. *Accept the Invitation:*
- After accepting the invitation, the first account will now have two accounts under the same subscription plan.
I sent a proof of concept: https://admin.alwaysdata.com/support/77431/375639-poc.mp4
*Impact:*
This vulnerability allows users to circumvent subscription limitations by creating multiple accounts under the same plan
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task