jeffgreco13/filament-breezy is vulnerable to Improper Authentication
65
Medium Risk
The PersonalInfo profile component saves an authenticated user's account email address straight from the form without requiring the current password, verifying the new address, or notifying the previous one. Someone with temporary access to an authenticated session can change the login email and then sign in with the existing password or trigger a password reset to an address they control. Because the email is typically both the login identifier and the password-reset destination, this results in persistent account takeover that survives the original session. The fix requires the current password, validated server-side, whenever the submitted email differs from the saved address.
You are affected if you are using a version that falls within the vulnerable range and your application relies on Breezy's default PersonalInfo profile component with email as the login identifier and/or password-reset destination.
jeffgreco13/filament-breezy is vulnerable to Improper Authentication in versions 2.0.0 - 2.6.4 and 3.0.0 - 3.2.6.
Upgrade the jeffgreco13/filament-breezy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant