Loading HuntDB...

Password token validation in Weblate Bypass #2

W
Weblate
Submitted None
Reported by footstep

Vulnerability Details

Technical details and impact analysis

Hi, I also found the bypass to #229987 and #243842. Reproduction Steps: 1. Add multiple emails to an account 2. Request password reset for all emails 3. Use the link in each to make the change 4. All link works! Shuaib

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted