Improper Password Reset Policy on https://hosted.weblate.org/
Low
W
Weblate
Submitted None
Actions:
Reported by
mrnull1337
Vulnerability Details
Technical details and impact analysis
Application should not allow the user to set the last 3-5 password in terms of secure design principles. It should give a warning or provide such avoidance while user is using repetitive usage of passwords.
Repro:
1. Try to set same old password via Password Reset link.
Fix: Application should avoid user to set last history of passwords to enforce the security.
Let me know if any further info is required.
Regards,
Mr_R3boot.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles