Reset password more than once with a reset link
Unknown
Vulnerability Details
Hi,
Though passwords reset links cannot be used more than once but I found a case where one could do so.
##Reproduction Steps
1. Request a Password Reset on demo.weblate.org
2. Click the reset link in email
3. Enter a new password
4. Click `Set my password`
5. Then you'll be redirected to the login page
6. Click `reset it` again
7. Fill the email and the captcha
8. Click `Reset my Password`
9. Instead of a message to check mail, you'll be prompted with the `Password Reset form`
10. Enter a new password and set it
11. Password successfully changed again
12. Repeat from 6
Shuaib
Actions
View on HackerOneReport Stats
- Report ID: 243594
- State: Closed
- Substate: resolved
- Upvotes: 5