Reset password more than once with a reset link
W
Weblate
Submitted None
Actions:
Reported by
footstep
Vulnerability Details
Technical details and impact analysis
Hi,
Though passwords reset links cannot be used more than once but I found a case where one could do so.
##Reproduction Steps
1. Request a Password Reset on demo.weblate.org
2. Click the reset link in email
3. Enter a new password
4. Click `Set my password`
5. Then you'll be redirected to the login page
6. Click `reset it` again
7. Fill the email and the captcha
8. Click `Reset my Password`
9. Instead of a message to check mail, you'll be prompted with the `Password Reset form`
10. Enter a new password and set it
11. Password successfully changed again
12. Repeat from 6
Shuaib
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors