Account Deleted without any confirmation
Unknown
Vulnerability Details
Hi
i don't know why this issue is not currently reported because its a big issue in mopub app here account is deleted without any confirmation
Steps to reproduce
1. Login your account Admin A
2. know add any user as admin access AdminB
3. using invited link create new account which is AdminB
4. Create many inventory using account AdminA
5. Know remove adminA from adminB
6. Know you see account AdminA is deleted from app
account A lost all their inventory and other data
here why account is deleted
know go to Login account A which is Deleted web app shows "This user has no accounts"
know go register new account with same email web app shows "This email address is already registered to another person"
the only one option is to live account again is when someone invited you
when someone invited you , after clicking on confirmation link account is activated automatically
when you reset the password , you receive password reset link , its reset the password but again same problem, during login same error =This user has no accounts
Account A have no any option to live again account until somone invite
why another account is able to do that?
hope you guys understand
Actions
View on HackerOneReport Stats
- Report ID: 42403
- State: Closed
- Substate: informative
- Upvotes: 3