-
Notifications
You must be signed in to change notification settings - Fork 143
Description
Severity: High (Security Risk)
Platform: Web
Describe the bug
The app.aixblock.io registration process allows users to create accounts without completing any verification steps (e.g., email verification, CAPTCHA, or phone number validation). This creates a vulnerability for spam, fake accounts, and potential abuse of the platform.
Steps to Reproduce
1.Navigate to app.aixblock.io.
2.Click "Sign Up" or "Create Account".
3.Fill in basic details (e.g., email, password, username).
4.Submit the form without completing any verification steps (e.g., no email confirmation, CAPTCHA, or phone number).
5.Observe that the account is created successfully without verification.
Expected behavior
1.Users should be required to complete at least one verification step (e.g., email confirmation, CAPTCHA, or phone number validation) to prevent abuse.
2.Verification should be mandatory before granting access to the platform.
Actual Behavior
No verification steps are enforced during account creation.
Users can bypass all checks and gain full access to the platform.
Desktop
Device: [Windows 11]
Browser/App Version: Chrome v139.0.7258.139
