Reset password more than once with a reset link #2
W
Weblate
Submitted None
Actions:
Reported by
footstep
Vulnerability Details
Technical details and impact analysis
Sequel to the fix on #243594, this is still possible.
##Reproduction Steps
1. Request password reset
- Load the link in email and set a new password
- Navigate to https://demo.weblate.org/accounts/reset/
- Fill the email and captcha
- You'll be prompted to enter a new password
NOTE: I figured that if action is not performed after a few minutes, then this doesn't work.
I suggest you make the link expire after use than setting a time frame.
Best!
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors