Loading HuntDB...

No password confirmation on changing primary email address

None
I
Inflection
Submitted None

Team Summary

Official summary from Inflection

Users may change the primary email address associated with their account without being required to confirm their password again. The security researcher reporting this proposed that we add a password confirmation field when performing an email change. After considering the issue, we don't intend to implement the suggestion at this time. This issue falls more into the "best practices" bucket than it does the vulnerability bucket, since this behavior in and of itself does not allow a user's account to be compromised.

Reported by papa_hecker

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Improper Access Control - Generic