Password Restriction
Low
W
Weblate
Submitted None
Actions:
Reported by
chols
Vulnerability Details
Technical details and impact analysis
Hi Weblate,
Hope you all have a good day!
Its a minor issue, but hope you'll fix it.
It seems like after changing password for example my current password is : mypassword1
And lets assume that the hacker got an access to my account, and me of course will change my password to ex. mypassword2.
There's no restriction when i change a new password with a similarity to the old password
In this way the attacker can still hack account easily because there's a similarity to the old and the new one.
Hope you'll triaged this.
Looking forward to your reply.
Best Regards,
Jolan Saluria
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles