logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-6152

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-6152

Description:
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.
Last updated date:
10/21/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/21/2024
Reference url to background

https://github.com/grafana/bugbounty/security/advisories/GHSA-3hv4-r2fm-h27f

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy