Reset password more than once with a reset link

Disclosed: 2017-08-21 18:04:08 By footstep To weblate
Unknown
Vulnerability Details
Hi, Though passwords reset links cannot be used more than once but I found a case where one could do so. ##Reproduction Steps 1. Request a Password Reset on demo.weblate.org 2. Click the reset link in email 3. Enter a new password 4. Click `Set my password` 5. Then you'll be redirected to the login page 6. Click `reset it` again 7. Fill the email and the captcha 8. Click `Reset my Password` 9. Instead of a message to check mail, you'll be prompted with the `Password Reset form` 10. Enter a new password and set it 11. Password successfully changed again 12. Repeat from 6 Shuaib
Actions
View on HackerOne
Report Stats
  • Report ID: 243594
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report