Adding Email lacks Password validation

Disclosed: 2017-06-28 02:12:18 By proabiral To weblate
Low
Vulnerability Details
## Affected URL: https://demo.weblate.org/accounts/email/ ## Issue: The account section of profile says: "You can add another email address on the Authentication tab." But there is no option of adding another email in Authentication. However, I was able to guess the above endpoint. The problem here is, the site lacks password validation for sensitive action like adding email id. ## Impact: The impact of the issue is similar to letting user change password without asking for old password. If any more info is needed feel free to contact me. :D Regards, Abiral
Actions
View on HackerOne
Report Stats
  • Report ID: 229869
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report