-
Bug
-
Resolution: Done
-
Low
-
None
-
1
-
Severity 1 - Critical
Issue Summary
If a user knows the email address or subscription details of another subscriber, they can go to the page and click on the "Subscribe to updates" button.
Once they enter the email of the other subscriber and hit subscribe, they are presented with a screen that has the option to change the subscriptions to the components and also the page. They can change component subscriptions, and unsubscribe the user from the page.
Note: To replicate this, the component subscriptions should be enabled on the page.
Steps to Reproduce
- Use an email address that has already subscribed to the same Statuspage to subscribe via Email.
- The page will be redirected to the Subscription Management Panel for this Email Address and you will be able to see the associated Webhook URL and make changes to the preference.
Expected Results
Users should not be able to change other users subscription preferences without some form of authentication
Actual Results
The page will be redirected to the Subscription Management Panel for this email address and you will be able to make changes to the subscription preferences, or unsubscribe entirely.
Workaround
N/A