A major flaw was discovered over the weekend in Steam's account login process that allowed users to reset any account knowing only the target's email address.
Exploiting the vulnerability was very easy. The malicious user could request a password reset, and then visit the special reset page by pressing OK.

The recovery page usually requests a code sent to your email address to verify your identity, but the Steam page was able to verify the victim's identity even with the code input box blank.
This means that anyone could hack any account on the service and change the password, without needing to have access to the recovery email address.
The error has now been fixed.
Steam told Kotaku that the bug only affected a few accounts from July 21st to 25th.
It would be a good idea if you are a user of the service to change your password, although the best way to protect yourself from this type of attack is to enable two-factor authentication.
