Praetorian discovered this vulnerability while examining the application’s user account management features. This feature does not require a user's current password to update their email address. This is shown in the figure below.
Ideally on Partner/Broker or company admin page, we should not able to update any field without asking old password. This password should not be sent to client side for verification.
- relates to
-
WT-1981 Localization for password authentication
-
- Closed
-
Transition | Time In Source Status | Execution Times |
---|
|
7d 23h 43m | 1 |
|
5s | 1 |
|
3s | 1 |
|
1h 8m | 1 |
|
33d 1h 21m | 1 |
|
44d 17h 54m | 1 |
|
23h 26m | 1 |
|
4s | 1 |
|
4d 6h 15m | 1 |
|
23m 27s | 1 |
|
12d 15h 37m | 1 |
|
43s | 1 |