Loading HuntDB...

Cloudflare is not properly deleting user's account

Medium
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

A vulnerability was discovered in Cloudflare’s User Deletion process which resulted in the current session not being terminated when a request to delete the user had been submitted. Cloudflare’s Engineering Team have fixed the vulnerability and user sessions are now invalidated once a user account deletion request is received.

Reported by csc_

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors