[hosted.weblate.org]Account Takeover
Low
W
Weblate
Submitted None
Actions:
Reported by
0xspade
Vulnerability Details
Technical details and impact analysis
Hello Team,
**Steps to Reproduce:**
* Go to Login Page
* Reset Your Password by Clicking `Reset it`.
* Put your email and answer the captcha.
* Go to your email and click your reset Link.
* You dont need to Change Your Password because you'll be logged in.
**Scenario**
Victim forgot to logout his/her Email Account on a Cafe/Internet Renting Shops. The Attacker Click the Reset Password link and because that Improper InValidation of Session on Password Reset Links lies in there. Attacker can gain access to Victim's Account.
Let me know if you need more information.
Best Regards,
Report Details
Additional information and metadata
State
Closed
Substate
Resolved