Issue with password change

Disclosed: 2015-05-28 04:44:05 By dawidczagan To security
Unknown
Vulnerability Details
When a password is changed in user's profile, then a notification about password change is sent to the user (email). This is good. However, user not always gets a notification about password change - when a password is changed via password reset link, then such a notification is not send to the user.
Actions
View on HackerOne
Report Stats
  • Report ID: 38343
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report