Adding Email lacks Password validation
Low
W
Weblate
Submitted None
Actions:
Reported by
proabiral
Vulnerability Details
Technical details and impact analysis
## Affected URL:
https://demo.weblate.org/accounts/email/
## Issue:
The account section of profile says: "You can add another email address on the Authentication tab." But there is no option of adding another email in Authentication.
However, I was able to guess the above endpoint.
The problem here is, the site lacks password validation for sensitive action like adding email id.
## Impact:
The impact of the issue is similar to letting user change password without asking for old password.
If any more info is needed feel free to contact me. :D
Regards,
Abiral
Report Details
Additional information and metadata
State
Closed
Substate
Resolved