Information disclosure (No rate limting in forgot password & other login)

Disclosed: 2018-04-14 08:47:26 By protector47 To imgur
Unknown
Vulnerability Details
Hi there, I noticed a small information leak which allows an attacker to check whether an email address is associated with an account.If your account is not associated with website then an error will become raise that **"That username or email was not found."** You should always return a status message like: **"If your email exists in our database, you'll receive a reset link"**. That way an attacker cannot distinguish between the two cases. Also you should add rate limiting :) Thanks,
Actions
View on HackerOne
Report Stats
  • Report ID: 91343
  • State: Closed
  • Substate: resolved
  • Upvotes: 29
Share this report