Unsubscribe Any User
None
I
Inflection
Submitted None
Team Summary
Official summary from Inflection
Researcher reported that HubSpot's "unsubscribe" feature allows any user to unsubscribe from marketing emails without having to confirm their email address. Inflection does not consider this a vulnerability, as we want to make it as easy as possible for users to stop receiving marketing emails that they don't wish to receive. This has no security impact on users' accounts, and they can always resubscribe to marketing emails if they wish.
Actions:
Reported by
hk755a
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Business Logic Errors