Broken Authentication and Session Management

Disclosed: 2014-08-05 05:37:48 By anandpingsafe To phabricator
Unknown
Vulnerability Details
Hi, Hope you are good! Steps to repro: 1) Create a Phabricator account having email address "[email protected]". 2) Now Logout and ask for password reset link. Don't use the password reset link sent to your mail address. 3) Login using the same password back and update your email address to "[email protected]" and verify the same. Remove "[email protected]". 4) Now logout and use the password reset link which was mailed to "[email protected]" in step 2. 5) Password will be changed. All previous password reset links should automatically expire once a user changes his email address. Please fix this. Best Regards Anand Prakash
Actions
View on HackerOne
Report Stats
  • Report ID: 17474
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report