Notify user about password change

Disclosed: 2017-05-17 18:14:12 By amsda To weblate
Low
Vulnerability Details
Hi, There is an issue with password reset functionality with Weblate: user is not receiving notification when he reset password. Good thing: when user change his info like profile update, password change. User get email notification for password change etc. Issue: user not always gets a notification about password change. When user change his password then a notification is not send to the user. It is good practice to always send email notification for user when a password change. Please let me know if more details required. thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 223609
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report