Hi,

The [email protected] list got this report. Would you mind to review it?

Thanks,
Victor

On Sat, Mar 20, 2021 at 5:24 PM shubham more
<[email protected]> wrote:
>
> Hii Team,
> I found vulnerbablity in website is Account takeover through change email.
> in change email without any cureent password conformation it can easily
> change /account takeover
>
> steps to reproduce:
> 1)go to website https://www.python.org/accounts/login/
> ex:Email:[email protected]
> 2)create new account and login
> 3)go to account ->click of Edit profile
> 4)click on edit profile page email address to new:[email protected]
> 5)click on save profile->after email change signout account
> 6)login new email address with old password also you can forget password
> ->forget password link send new email
> 7)then sign account
> Result Account takeover through change email.
>
>
> Impact:
> attacker easily takeover account
>
> poc:screenshot
> Thank you.
> _______________________________________________
> PSRT mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> https://mail.python.org/mailman3/lists/psrt.python.org/
> Member address: [email protected]



-- 
Night gathers, and now my watch begins. It shall not end until my death.
_______________________________________________
pydotorg-www mailing list
[email protected]
https://mail.python.org/mailman/listinfo/pydotorg-www

Reply via email to