Loading HuntDB...

Reset password more than once with a reset link

W
Weblate
Submitted None
Reported by footstep

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
Hi, Though passwords reset links cannot be used more than once but I found a case where one could do so. ##Reproduction Steps 1. Request a Password Reset on demo.weblate.org 2. Click the reset link in email 3. Enter a new password 4. Click `Set my password` 5. Then you'll be redirected to the login page 6. Click `reset it` again 7. Fill the email and the captcha 8. Click `Reset my Password` 9. Instead of a message to check mail, you'll be prompted with the `Password Reset form` 10. Enter a new password and set it 11. Password successfully changed again 12. Repeat from 6 Shuaib

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors