User enumeration via forgot password error message

Disclosed: 2017-10-27 08:05:08 By kiddie To infogram
Medium
Vulnerability Details
Hi Team, Vulnerable URL : https://infogram.com/forgot Description: During testing forgot password field whether it's rate limiting is working or not, I noticed forgot password field is vulnerable to user enumeration. When user enter email id which is not available into database it shows an error " E-mail not recognized". Mitigation: handle the above situation correctly, e.g.: "Reset link is send to email : [email protected]". This doesn't inform the attacker E-mail not recognized and make enumeration more difficult Thanks and regards, Kiddie Refer Ticket : #77067 #123496
Actions
View on HackerOne
Report Stats
  • Report ID: 282564
  • State: Closed
  • Substate: duplicate
  • Upvotes: 1
Share this report