Updating payout preference to CurrencyCloud doesn't notify user via email
None
H
HackerOne
Submitted None
Actions:
Reported by
dr_dragon
Vulnerability Details
Technical details and impact analysis
When change payment method in user's payments, then a notification about
Change payment method is sent to the user (email).
However, user not always gets a notification about change payment method - when change payment method via add payout method on Payout Methods, then such a notification is not send to the user (email).
Also,
when user try to change payment method , they were asked to verify the request by entering hackerone password. for the same reason a verification should be there on add payout method.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Violation of Secure Design Principles