Password reset link not expired at Stocky App

Disclosed: 2020-08-18 22:53:55 By ayyoub To shopify
Unknown
Vulnerability Details
You can use password reset link to reset password multiple times. Steps: 1. Go to `https://stocky.shopifyapps.com/users/forgotten_password` and Send the password reset link to your email. (if this page doesn't appear you should add login details via this `https://stocky.shopifyapps.com/preferences/users` ) {F869115} 2. Go to your email inbox you see reset token like this `https://stocky.shopifyapps.com/users/new_password?reset_token=your-reset-token`and click the link to change password. you can use this link many times to reset password ## Impact Password Reset Link not expiring after changing password
Actions
View on HackerOne
Report Stats
  • Report ID: 898841
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report