-
Notifications
You must be signed in to change notification settings - Fork 9.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Issue] Removed email disclosure #39574
Comments
Hi @engcom-Bravo. Thank you for working on this issue.
|
Hi @Mohamed-Asar, Thanks for your reporting and collaboration. Could you please elaborate the steps to reproduce and if possible provide screenshots to proceed further. Thanks. |
Hi @engcom-Bravo, Navigate to the account confirmation page: customer/account/confirmation. Enter an email address that is associated with an existing and already confirmed account. The page will redirect to the login page and display a message stating that the account does not require confirmation. If you enter an email address that does not have an associated account, an error message will appear stating that the email is incorrect. This behavior allows anyone to determine whether a customer account exists on the site, potentially exposing account status information. |
Hi @Mohamed-Asar, Thanks for your update. We are considering as Enhancement to proceed further marking this as Feature Request. Thanks. |
This issue is automatically created based on existing pull request: #39570: Removed email disclosure
Description (*)
Display an error message indicating an incorrect email if the entered email is not required to confirm the account, regardless of whether the customer exists or not.
customer/account/confirmation
Contribution checklist (*)
The text was updated successfully, but these errors were encountered: