Loading HuntDB...

Unauthorized User Can Delete Any User Account

None
N
Nord Security
Submitted None
Reported by d4rk_g1rl

Vulnerability Details

Technical details and impact analysis

Privacy Violation
###DESCRIPTION: Your help desk allows creating tickets by email. Which means the user can send an email to the NordVPN support email to a add a new ticket to his activities. So when you send an email to `[email protected]` from your email address, this ticket will be created on the account that you have registered with the email. ###Steps To Reproduce: 1. Navigate this page: https://ucp.nordvpn.com/login/ 2. Try to click the Email button below. 3. Try to fill up the form. See my attached photo. {F726511} 4. As you notice I am not Authorized User and has no account in NordVPN. 5. Try to use the victim Email when deleting an account. 6. Few hours later. 7. The account of the victim was deleted successfully. ######Victim 1 : {F726515} ######Victim 2 : {F726516} #####Note: The account was remove from the database ###Recommendation fix * Critical actions like changing email or close account should be verify by sending PIN code to user email and asks him to reply back the code again. * The second fix and I don’t like is disable creating tickets via your support email for more security * Sending a confirmation link when deleting an account Regards, ## Impact The Unauthorized User Can Delete Any User Account

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Privacy Violation