Password token validation in Weblate Bypass #2
W
Weblate
Submitted None
Actions:
Reported by
footstep
Vulnerability Details
Technical details and impact analysis
Hi,
I also found the bypass to #229987 and #243842.
Reproduction Steps:
1. Add multiple emails to an account
2. Request password reset for all emails
3. Use the link in each to make the change
4. All link works!
Shuaib
Report Details
Additional information and metadata
State
Closed
Substate
Resolved