-
-
Notifications
You must be signed in to change notification settings - Fork 667
Closed
Description
Good evening,
My name is suleman Malik and im security researcher. I have found a security vulnerability on https://www.python.org/accounts/password/reset/. Password reset is vulnerable to email flooding vuln. Image is attached with this report.
===Mitigation===
Use rate limit function or captcha in order to stop this kind of attack.
Here are two links that are disclosing server side information including server name version and operating system being used on python.org.
http://mail.python.org/
https://hg.python.org/
Looking forward!
Suleman Malik
InfoSec Researcher
www.sulemanmalik.com

Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels