Loading HuntDB...

No Rate Limit On Forgot Password Page

Low
K
Kaspersky
Submitted None

Team Summary

Official summary from Kaspersky

Reported security issue allowed a potential attacker to abuse the password recovery option on our My Kaspersky portal for mass sending of password recovery messages. This was fixed with a password reset throttling feature to protect our service from its abuse by third parties. Note that this problem is related to our internal services and doesn't require any actions from side of our users.

Reported by hacker-yadav

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic