Logic issue in email change process
Low
L
Legal Robot
Submitted None
Team Summary
Official summary from Legal Robot
A security researcher discovered that during the email change process, the new account was not properly validated before making it available for login. As a result of this report, Legal Robot checks that both the current address confirms the change and the new address is verified before proceeding. Also, sign in attempts using the new email address are blocked until the new email is verified.
Actions:
Reported by
safehacker_2715
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic