-
-
Notifications
You must be signed in to change notification settings - Fork 4.8k
Closed
Description
More results from our penetration testing....
Steps to reproduce:-
- Create an account having an email address "a@site.com".
- Now Logout and ask for password reset link. ( Don't use that password reset link. )
- Login using the same password back and update your email address to "b@site.com"
- Now logout and use the password reset link which was mailed to "a@site.com" in step 2.
- Password will be changed.
Recommendation:-
All previous password reset links should automatically expire once a user changes his/her email address.
Metadata
Metadata
Assignees
Labels
No labels