Running 2 accounts with a single email
None
W
Weblate
Submitted None
Actions:
Reported by
footstep
Vulnerability Details
Technical details and impact analysis
Hi,
While testing, I found a logic flaw which made me to make two accounts with a single email
###Reproduction Steps
- You need 3 emails (Gmail to be precise)
- Register 2 accounts with 2 different emails
- On account 1, add a new email (3rd email) using the Google Auth
- Then delete the previous email
- add a new email (3rd email) using the Google Auth
- Logout and Login, you'll see one with email and other with Google logo
- Delete the one with Google logo (Auth) leaving the other
- Navigate to https://myaccount.google.com/permissions and remove `Weblate`
- Do the same on account 2 preferably in another browser without the last step (*Navigate....*)
- Now 2 accounts have one email.
- Logout and login (account 2) and you'll see a message like below
{F179708}
Regards,
Shuaib
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors