USER Account is not being deleted after user "Delete Account" from DASHBOARD

Disclosed: 2014-08-17 00:45:13 By faisalahmed To digitalsellz
Unknown
Vulnerability Details
Hello, There is an option on DigitalSellz USER DASHBOARD called "Delete Account" https://www.digitalsellz.com/user/#/profile I tried to used this feature, i deleted my account with two simple clicks. than i visited my Public Profile link (https://www.digitalsellz.com/public_profile/[PROFILE ID]) or https://www.digitalsellz.com/USERNAME) , it's still valid. i tried to login again and found out my profile is not been deleted, every information i added is still there, like i never tried to delete it. I decided to report it but thought lets try this "Delete Account" feature after adding any product on my account. so I added a TEST product and than deleted my account. This time my profile is been deleted from DigitalSellz Database completely.. now I'm no longer able to see my Public Profile or log in my account. it says, **No account exists with this email** means Profile is deleted successfully. Now Here my question is, it this whole process is a feature of DigitalSellz ? i mean is it in your feature that a DigitalSellz Account won't be deleted if user didn't added any PRODUCT on it? (although it shows a message **Your account deleted successfully** when user delete his/her account, no matter if there is any product added on the account or not) If it not in your feature, i think you should fix this ASAP. If it is your feature, than sorry about the report. i was confused, that's why i reported it.. Best Wishes!
Actions
View on HackerOne
Report Stats
  • Report ID: 20305
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report