Description
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanently take over the victim's account.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version before 12.128.2
6685e5f11adef257bf3d085e481f4d8ebcec602e (git)
Credits
Naitik Gupta
References
github.com/.../capgo/security/advisories/GHSA-w56g-jv78-hf79
github.com/.../capgo/security/advisories/GHSA-w56g-jv78-hf79
github.com/...ommit/6685e5f11adef257bf3d085e481f4d8ebcec602e
www.vulncheck.com/...-unauthenticated-email-change-mechanism