LaraBug / LaraBug

Laravel error reporting tool
https://www.larabug.com
MIT License
267 stars 58 forks source link

Email is being possible to change without verification #89

Open mrshoikot opened 1 year ago

mrshoikot commented 1 year ago

When someone tries to update email in their profile, it doesn't send a verification link to the new email address for verification. So, anybody can set any email address for their account. The vital risk here is that if someone enters the wrong email they'll no longer receive email notification and password reset won't be possible.