Skip to content

Server side info disclosure/ Spamming inbox #1041

@sulemanmalik003

Description

@sulemanmalik003

Good evening,

My name is suleman Malik and im security researcher. I have found a security vulnerability on https://www.python.org/accounts/password/reset/. Password reset is vulnerable to email flooding vuln. Image is attached with this report.

===Mitigation===
Use rate limit function or captcha in order to stop this kind of attack.

Here are two links that are disclosing server side information including server name version and operating system being used on python.org.

http://mail.python.org/
https://hg.python.org/

Looking forward!

Suleman Malik
InfoSec Researcher
www.sulemanmalik.com
python

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions