No notification on Password Change
Medium
I
Infogram
Submitted None
Actions:
Reported by
kiddie
Vulnerability Details
Technical details and impact analysis
Hi Team,
Description :
I noticed there is an issue with password reset functionality user is not receiving notification when he reset password. Even though when user change password through profile, not getting an email notification.
Issue: user not always gets a notification about password change. When user change his password then a notification is not send to the user.
It would be critical issue if user kept his/her account logged-in into PC or cyber cafe, then attacker can change his/her password without knowing to the user.
It is good practice to always send email notification for user when a password change.
Please let me know if more details required.
thanks and regards,
Kiddie..!!
Refer Ticket : #223609
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate