Access to completion page without performing any action
None
W
Weblate
Submitted None
Actions:
Reported by
footstep
Vulnerability Details
Technical details and impact analysis
Hi!,
This is much of a best practice as it doesn't have much impact on the user. But I believe you may want to know.
After making a registration or on finalizing a password reset, one is redirected to a page, https://demo.weblate.org/accounts/email-sent/. I noticed that even without making any of the two actions stated above, the page is still accessible.
Regards,
Shuaib
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic