Spamming any user from Reset Password Function
Low
W
Weblate
Submitted None
Actions:
Reported by
atruba
Vulnerability Details
Technical details and impact analysis
It is possible to spam any user whose email-id is known.
csrfmiddlewaretoken token can be used more than one.
Users can be spammed heavily by just Brute force attack on password reset page.
Implementtion:
Implement a Captcha.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles