Weak password policy

Disclosed: 2017-08-18 05:21:02 By platinum1933 To weblate
Low
Vulnerability Details
Hi team, i get to know that you are using strong password policy. i gone through application and checked for that. and get to know that as per ISO9001 security compliance weak password policy. #Steps : 1) signup with https://hosted.weblate.org/ with password vikas@123 2) forget password and change to some other password 3) change again to vikas@123 it will allow. as per strong password security last 5 used password should not allowed from application, #Scenario: if by mistake attacker get to know victim's password and then only victim will change password. again victim changed and he changed to same password that will not always good policy. Thanks.
Actions
View on HackerOne
Report Stats
  • Report ID: 224572
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report