• 0 Posts
  • 4 Comments
Joined 2 years ago
cake
Cake day: November 1st, 2023

help-circle

  • Perhaps it’s something that I’m missing. What do you mean when you say their email is confirmed?

    Usually when this happens, it’s a result of someone taking advantage of an application vulnerability, e.g. sql injection. Sometimes it’s more serious, like a script uploaded and a privilege escalation to execute it. The email value written to your database could be anything.

    Not to condescend, but this is a good learning experience. If they were able to write to your db, they could likely also read from it, dump the whole thing and harvest the data.