cve/2023/CVE-2023-6152.md
2024-06-18 02:51:15 +02:00

820 B

CVE-2023-6152

Description

A user changing their email after signing up and verifying it can change it without verification in profile settings.The configuration option "verify_email_enabled" will only validate email only on sign up.

POC

Reference

Github

No PoCs found on GitHub currently.