Loading HuntDB...

No rate limiting on password reset page

Low
C
Clario
Submitted None

Team Summary

Official summary from Clario

### Summary `https://account.mackeeper.com` hasn't enforced rate limiting on the password-reset page. By this, an attacker can send huge amounts of requests to the server for changing the password. ### Steps to Reproduce 1. Go to the forgot password page and enter your email. 2. Turn 'Intercept on' in Burp Suite and Click on 'Reset Password'. 3. Now send that request to the intruder and add the point of attack anywhere you like

Reported by karna__

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$50.00

Submitted

Weakness

Business Logic Errors