You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I found an issue that your application is allowing user to set new password same as that of the old password.
As per secure password policy application should not allow same old password value to be used in setting new password value cos there might be possibility that old password might be exposed or leaked to an adversary so its advisable on application end to enforce strong password policy and should implement check to not to allow user to set old password value in new password value.
Step to Reproduce
1- Go to https://username.matomo.cloud/
2- Click on Lost password
3- enter old password as new password site accept and logged you in
4- Don't need to chek email and Authorized your password change request
The problem is that,today attackers are accessing particular user account by knowing his other account passwords in other sites and also by knowing the old passwords used by him, So allowing users to set old password is some what a typical issue.
The text was updated successfully, but these errors were encountered:
Thanks for creating this report @niteshpatel798
Our product team will consider this for future improvements.
For issues that make Matomo more secure. Please report issues through HackerOne and not in Github.
Something that might be a bug, but can't be reproduced (yet).
Oct 11, 2022