Missing Account Deletion Notification
W
WakaTime
Submitted None
Actions:
Reported by
pavanw3b
Vulnerability Details
Technical details and impact analysis
Currently, there is no email notification sent out when the account was deleted.
I understand it asks for the password to delete but when an attacker somehow get's the credentials, he can only 'read' users data without alarming the user. It would stop him if he knows the user would come to know immediately when all the data was deleted.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved