User Enumeration when adding email to account
Low
W
Weblate
Submitted None
Actions:
Reported by
atruba
Vulnerability Details
Technical details and impact analysis
It is possible to find all the Register emails which can be use for spam or other purposes
csrfmiddlewaretoken token can be used more than one.
All Register Email can be found by just brute force attack.
Your web endpoint https://demo.weblate.org/accounts/email/ when changing email after login.
Implementtion:
Implement a Captcha.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved