Updating payout preference to CurrencyCloud doesn't notify user via email

Disclosed: 2018-01-31 02:05:10 By dr_dragon To security
None
Vulnerability Details
When change payment method in user's payments, then a notification about Change payment method is sent to the user (email). However, user not always gets a notification about change payment method - when change payment method via add payout method on Payout Methods, then such a notification is not send to the user (email). Also, when user try to change payment method , they were asked to verify the request by entering hackerone password. for the same reason a verification should be there on add payout method.
Actions
View on HackerOne
Report Stats
  • Report ID: 240083
  • State: Closed
  • Substate: resolved
  • Upvotes: 35
Share this report