No rate limiting on password reset page
Low
C
Clario
Submitted None
Team Summary
Official summary from Clario
### Summary `https://account.mackeeper.com` hasn't enforced rate limiting on the password-reset page. By this, an attacker can send huge amounts of requests to the server for changing the password. ### Steps to Reproduce 1. Go to the forgot password page and enter your email. 2. Turn 'Intercept on' in Burp Suite and Click on 'Reset Password'. 3. Now send that request to the intruder and add the point of attack anywhere you like
Actions:
Reported by
karna__
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$50.00
Submitted
Weakness
Business Logic Errors