Missing Account Deletion Notification

Disclosed: 2017-07-03 06:41:17 By pavanw3b To wakatime
Unknown
Vulnerability Details
Currently, there is no email notification sent out when the account was deleted. I understand it asks for the password to delete but when an attacker somehow get's the credentials, he can only 'read' users data without alarming the user. It would stop him if he knows the user would come to know immediately when all the data was deleted.
Actions
View on HackerOne
Report Stats
  • Report ID: 245311
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report