🔥 Account Takeover via Duplicate Registration — A 1500 Euro Jackpot
The Bug
Found a critical account takeover in a web application’s registration flow.The platform allowed creating the same account (same email) from a different session, even though the account already existed.
Step-by-Step PoC
Create account with em...
thesecurityguy.hashnode.dev1 min read