Full Name Overwrite on Third party login

Disclosed: 2017-08-21 17:47:12 By footstep To weblate
Unknown
Vulnerability Details
##Description After one might have logged in on a browser using the *Third party login* (Google) and have made changes to the account like the `Full name`. Making a *third party login* on another browser using the same email overwrites the `Full name` to the name on the email. One would know he is logged in the same account because the username remains the same. #####NOTE: This happens when you logout and make a `third party login` again. The `Full name` changes. Shuaib.
Actions
View on HackerOne
Report Stats
  • Report ID: 241598
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report