The affected asset is redacted at the researcher's request.
Summary:
An attacker can register an account using an email address they do not own without verifying it. The email is immediately marked as registered, preventing the legitimate owner from registering with the same address.
Steps To Reproduce:
1.Create an account using an email address you do not own victim@gmail.com.
2.Do not verify the email address.
3.From another browser/session, attempt to register using victim@gmail.com.
4.The application rejects the registration with "Email already exists in the database".
Impact
An attacker can reserve arbitrary email addresses without proving ownership, preventing their legitimate owners from registering accounts with those addresses.