Loading HuntDB...

Running 2 accounts with a single email

None
W
Weblate
Submitted None
Reported by footstep

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
Hi, While testing, I found a logic flaw which made me to make two accounts with a single email ###Reproduction Steps - You need 3 emails (Gmail to be precise) - Register 2 accounts with 2 different emails - On account 1, add a new email (3rd email) using the Google Auth - Then delete the previous email - add a new email (3rd email) using the Google Auth - Logout and Login, you'll see one with email and other with Google logo - Delete the one with Google logo (Auth) leaving the other - Navigate to https://myaccount.google.com/permissions and remove `Weblate` - Do the same on account 2 preferably in another browser without the last step (*Navigate....*) - Now 2 accounts have one email. - Logout and login (account 2) and you'll see a message like below {F179708} Regards, Shuaib

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors