Disabled user can reset their password

Disclosed: 2020-03-01 15:01:45 By egrep To nextcloud
None
Vulnerability Details
Steps: 1) Create user and disable the account 2) Goto reset password and enter disabled user's email address. Password reset link sent and he can reset the password using that link. The point is : Disabled user can still access their account via reset password page. This is a very minor issue
Actions
View on HackerOne
Report Stats
  • Report ID: 261297
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report