Closed Bug 1282814 Opened 8 years ago Closed 8 years ago

possible to send an e-mail with somebody else's address

Categories

(Thunderbird :: Security, defect)

45 Branch
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1254666

People

(Reporter: masclauxf, Unassigned)

Details

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0
Build ID: 20160604131506

Steps to reproduce:

I received an email from a friend. This e-mail was also sent to other people than me. I wanted to use this e-mail as a "new message" ("modify as a new message"). But it was not my address that was reported in the "sender" box but the address of one of the previous receiver. I did not realize and I sent the e-mail.


Actual results:

 Everybody received the message like it was not my message but the message of somebody else. Second test : Actually it is possible to modify the "sender box" with keyboard when using the "modify as a new message" option. It can write whatever I want in here.


Expected results:

It should not be possible to modify the sender's address using the keyboard.
It should not be possible to send a message with a random "sender" or a "sender" that is not recorded in any local account.
The name of the owner's account should appear in the "sender" box when using "modify as a new message" and it should not be possible to alter it by typing
this is all about bug 1254666
Group: mail-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.