No error or notification on Reset password page
Unknown
Vulnerability Details
Hello
I found that there is no error occurring at Reset password page. There should error occur when user enter the wrong email-id or the entered password is used in 180 previous days or token got expired because from previous reset link also the page got opened so, user would not be able to understand the reason why he/she could not able to reset the password. Although it is not a security bug but my request to you to add error message or notification for these things on Reset Password page for user convenience.
Thanks
Actions
View on HackerOneReport Stats
- Report ID: 255100
- State: Closed
- Substate: resolved
- Upvotes: 4