Skip to content

Information leak about subscribed users #183

@robert-kisteleki

Description

@robert-kisteleki

If one tries to subscribe a second time, the behaviour is to show an error message "Your e-mail address has already been subscribed to.". This can be used by anyone to evaluate if a particular email is subscribed.

I think a better solution would be to show the default "thank you" page (with or without confirmation as per settings) and perhaps not even sending an actual mail.

The concept may be applicable with other functions, I haven't yet explored them all ;-)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions