Bug Description:


SUBMITTED BY: tanishqjaichand

DATE: Feb. 20, 2017, 7:02 a.m.

FORMAT: Text only

SIZE: 710 Bytes

HITS: 2325

  1. Bug Description:
  2. Password reset link still works after email changed. This bug is most commonly found in big name sites.
  3. Steps:
  4. 1) Create a account having email address "a@x.com".
  5. 2) Now Logout and request for password reset link. Don't use that reset link.
  6. 3) Login using the same password back and update your email address to "b@x.com" and verify it.
  7. 4) Use the password reset link which sent to your "a@x.com" in step 2.
  8. 5) At last, Open that link, fill all form fields and submit the request
  9. 6) If you see something like this "Password is changed", Then that site is vulnerable
  10. Suggestion:-
  11. All previous password reset links should automatically expire once a user changes his email address.

comments powered by Disqus