Hey noob, your E-Mail is showing!

I tried too hard to come up with a funny title.

My friend DataSynchronized reported this to me, and I thought I’d post it here.

When you go to your settings page, your email is hidden. However, it is possible to retrieve the email address by going to: Log in to Roblox

Since the email address is used as a way to verify ownership over an account, this could be used to trick Customer Support into turning an account over to someone who isn’t supposed to own it.

Video of the bug: https://www.youtube.com/watch?v=Uv-K0ZHJq_Q&feature=youtu.be

4 Likes

That’s pretty interesting. Take off the /json and you get the account page where you have to input your password to change the hidden email. Add the /json and you have the email in plain text.

And what is age bracket?

I think it might just be the same thing as UserAbove13

This has been the case for a long time.
Another way to see the email is by “registering” on rbxdev and going to your settings.
What I noticed though, although I’m not sure:
If you change your roblox mail, your rbxdev mail doesn’t (immediatly?).
(Don’t know if it takes some time, as I changed my email back a minute later)

I reported this a while back.