Loading HuntDB...

Improper Password Reset Policy on https://hosted.weblate.org/

Low
W
Weblate
Submitted None
Reported by mrnull1337

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Application should not allow the user to set the last 3-5 password in terms of secure design principles. It should give a warning or provide such avoidance while user is using repetitive usage of passwords. Repro: 1. Try to set same old password via Password Reset link. Fix: Application should avoid user to set last history of passwords to enforce the security. Let me know if any further info is required. Regards, Mr_R3boot.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles