Loading HuntDB...

Password reset link not expiring after changing password in settings

Low
B
Basecamp
Submitted None

Team Summary

Official summary from Basecamp

@blackbibin reported password reset link not expiring when password was updated from an active session, by going to the Account's Login & Security setting. We were only expiring password reset links when the password was updated through a password reset request. Now we expire password reset links whenever a password is updated (besides regular time-based expiration).

Reported by zukito

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$250.00

Submitted

Weakness

Improper Authentication - Generic