Password reset token issue

Disclosed: 2017-09-05 00:23:31 By ghoibsec To legalrobot
Low
Vulnerability Details
##Summary Can still change password without token ##Step to Reproduce - Request for password reset link. - Go to email and click on password reset link https://app.legalrobot.com/password-reset/token?v=uWe_yFJS0-N9fIk0nG0b0NZ70lkwNNi7RdUZu0KhiaX - Now remove the token and use the link https://app.legalrobot.com/password-reset Observe that able to reset the password without the token. ##Fix : Always password reset link should work with a valid token. ##Reference : https://hackerone.com/reports/253934 Thanks, tell me if you need video. i'll create one.
Actions
View on HackerOne
Report Stats
  • Report ID: 265775
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report