Loading HuntDB...

Lack of Password Confirmation When Changing Email

W
WakaTime
Submitted None
Reported by pratyushjanghel

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
When any user wants to change the password, current password is asked for proceeding the request. This should also be implemented on changing the email. Attack Scenerio : When some forget to logout from the account in a publc computer, anyone can change the email to its own and verify it. And after that using the forget password feature, it can change the password too. Reference From : #546 Best Regards, Pratyush Janghel

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles