https://bugzilla.wikimedia.org/show_bug.cgi?id=67248
Bug ID: 67248
Summary: Make sure, the given token is used for the function
Product: MediaWiki extensions
Version: master
Hardware: All
OS: All
Status: NEW
Severity: major
Priority: Unprioritized
Component: GoogleLogin
Assignee: [email protected]
Reporter: [email protected]
CC: [email protected]
Web browser: ---
Mobile Platform: ---
Actually, if you change the action in form (maybe form to unlink google and
wiki account) to /Create you can create a new User account, also when you are
logged in and the google id is linked to another account (the Google id is
still linked to the "old" account, so no account compromise).
--
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l