Unauthorized User Can Delete Any User Account
None
N
Nord Security
Submitted None
Actions:
Reported by
d4rk_g1rl
Vulnerability Details
Technical details and impact analysis
###DESCRIPTION:
Your help desk allows creating tickets by email. Which means the user can send an email to the NordVPN support email to a add a new ticket to his activities. So when you send an email to `[email protected]` from your email address, this ticket will be created on the account that you have registered with the email.
###Steps To Reproduce:
1. Navigate this page:
https://ucp.nordvpn.com/login/
2. Try to click the Email button below.
3. Try to fill up the form. See my attached photo.
{F726511}
4. As you notice I am not Authorized User and has no account in NordVPN.
5. Try to use the victim Email when deleting an account.
6. Few hours later.
7. The account of the victim was deleted successfully.
######Victim 1 :
{F726515}
######Victim 2 :
{F726516}
#####Note: The account was remove from the database
###Recommendation fix
* Critical actions like changing email or close account should be verify by sending PIN code to user email and asks him to reply back the code again.
* The second fix and I don’t like is disable creating tickets via your support email for more security
* Sending a confirmation link when deleting an account
Regards,
## Impact
The Unauthorized User Can Delete Any User Account
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Privacy Violation