Running 2 accounts with a single email [Part 2]
Unknown
Vulnerability Details
Following the fix on #224072, I decided to try this in another way and it worked!
##Reproduction Steps
1. Login with Github on Browser1 and set a password to it.
- With another email, signup on Weblate on Browser2
- In the new account on Browser2, do the following:
> Confirm email and Set a Password
Add a Google Account with the same email used to signup Github
Now, disconnect the email used to signup
So, it the email is default to same email on the other account
4. Reload both browsers to confirm, https://hosted.weblate.org/accounts/profile/#account
- Logout any of the browsers
- Trying to login with the email and any of the set passwords pops an **Internal Server Error**
Accompanying screenshots are attached below.
Actions
View on HackerOneReport Stats
- Report ID: 241608
- State: Closed
- Substate: resolved
- Upvotes: 5