Password Restriction
Low
Vulnerability Details
Hi Weblate,
Hope you all have a good day!
Its a minor issue, but hope you'll fix it.
It seems like after changing password for example my current password is : mypassword1
And lets assume that the hacker got an access to my account, and me of course will change my password to ex. mypassword2.
There's no restriction when i change a new password with a similarity to the old password
In this way the attacker can still hack account easily because there's a similarity to the old and the new one.
Hope you'll triaged this.
Looking forward to your reply.
Best Regards,
Jolan Saluria
Actions
View on HackerOneReport Stats
- Report ID: 229920
- State: Closed
- Substate: resolved
- Upvotes: 12