1day
Jan 22, 2024

--

The response of the reset email sending itself had the session which is appended to the URL. So an attacker could just use that session id and create url

--

--

1day
1day

Written by 1day

I love computers because of the bugs in it

No responses yet