Loading HuntDB...

User Enumeration when adding email to account

Low
W
Weblate
Submitted None
Reported by atruba

Vulnerability Details

Technical details and impact analysis

It is possible to find all the Register emails which can be use for spam or other purposes csrfmiddlewaretoken token can be used more than one. All Register Email can be found by just brute force attack. Your web endpoint https://demo.weblate.org/accounts/email/ when changing email after login. Implementtion: Implement a Captcha.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted