Loading HuntDB...

No notification on Password Change

Medium
I
Infogram
Submitted None
Reported by kiddie

Vulnerability Details

Technical details and impact analysis

Hi Team, Description : I noticed there is an issue with password reset functionality user is not receiving notification when he reset password. Even though when user change password through profile, not getting an email notification. Issue: user not always gets a notification about password change. When user change his password then a notification is not send to the user. It would be critical issue if user kept his/her account logged-in into PC or cyber cafe, then attacker can change his/her password without knowing to the user. It is good practice to always send email notification for user when a password change. Please let me know if more details required. thanks and regards, Kiddie..!! Refer Ticket : #223609

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted