Broken Authentication and Session Management

Disclosed: 2014-11-17 14:30:48 By vinothkumar To secret
Unknown
Vulnerability Details
Hi, Hope you are good! Steps to Reproduce: 1) Create a Secret account having email address "[email protected]". 2) Now Logout and ask for password reset link. Don't use the password reset link. 3) Login using the same password back and update your email address to "[email protected]" and verify the same. 4) Now logout and use the password reset link which was mailed to "[email protected]" in step 2. 5) Password will be changed. All previous password reset links should automatically expire once a user changes his email address. Please let me know if this can be fixed. Best Regards, Vinoth Kumar J
Actions
View on HackerOne
Report Stats
  • Report ID: 23579
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report