Loading HuntDB...

[Cross-domain Referer leakage] Password reset token leakage via referer

Low
L
Legal Robot
Submitted None

Team Summary

Official summary from Legal Robot

A security researcher discovered that sensitive information, like password reset tokens could still be leaked to analytics services like Google Analytics or via the Referer [sic] header. Even though tokens were immediately invalidated, we decided to re-engineer the process to eliminate any possibility of token leakage.

Reported by r3y

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure