Loading HuntDB...

Password token validation in https://demo.weblate.org/

W
Weblate
Submitted None
Reported by brdoors3

Vulnerability Details

Technical details and impact analysis

Improper Authentication - Generic
Hi team, I noticed that when requesting multiple reset links at https://demo.weblate.org/ all tokens are valid and can be used. In numerous applications the following policy is adopted as an additional security measure: - keep valid only that token with shorter lifetime (last requested) or - invalidate all reset links generated after successful use of one of these tokens Please check it.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authentication - Generic