No password confirmation on changing primary email address
None
I
Inflection
Submitted None
Team Summary
Official summary from Inflection
Users may change the primary email address associated with their account without being required to confirm their password again. The security researcher reporting this proposed that we add a password confirmation field when performing an email change. After considering the issue, we don't intend to implement the suggestion at this time. This issue falls more into the "best practices" bucket than it does the vulnerability bucket, since this behavior in and of itself does not allow a user's account to be compromised.
Actions:
Reported by
papa_hecker
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Access Control - Generic