Hi, The [email protected] list got this report. Would you mind to review it?
Thanks, Victor On Sat, Mar 20, 2021 at 5:24 PM shubham more <[email protected]> wrote: > > Hii Team, > I found vulnerbablity in website is Account takeover through change email. > in change email without any cureent password conformation it can easily > change /account takeover > > steps to reproduce: > 1)go to website https://www.python.org/accounts/login/ > ex:Email:[email protected] > 2)create new account and login > 3)go to account ->click of Edit profile > 4)click on edit profile page email address to new:[email protected] > 5)click on save profile->after email change signout account > 6)login new email address with old password also you can forget password > ->forget password link send new email > 7)then sign account > Result Account takeover through change email. > > > Impact: > attacker easily takeover account > > poc:screenshot > Thank you. > _______________________________________________ > PSRT mailing list -- [email protected] > To unsubscribe send an email to [email protected] > https://mail.python.org/mailman3/lists/psrt.python.org/ > Member address: [email protected] -- Night gathers, and now my watch begins. It shall not end until my death. _______________________________________________ pydotorg-www mailing list [email protected] https://mail.python.org/mailman/listinfo/pydotorg-www
