No error or notification on Reset password page

Disclosed: 2017-09-26 01:07:11 By princesinha To legalrobot
Unknown
Vulnerability Details
Hello I found that there is no error occurring at Reset password page. There should error occur when user enter the wrong email-id or the entered password is used in 180 previous days or token got expired because from previous reset link also the page got opened so, user would not be able to understand the reason why he/she could not able to reset the password. Although it is not a security bug but my request to you to add error message or notification for these things on Reset Password page for user convenience. Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 255100
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report