You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I do wonder if we should (non-normatively) mention the concern that having a well-known password change url could be used for nefarious purposes (e.g. sending a lot of emails, denial of service if there’s a rate limit on password changes, authentication attacks against security questions, etc.).
The text was updated successfully, but these errors were encountered:
Missing Function Level Access Control issue. Possibly this functionality may be hidden till user is privileged. and Hence, this allows a low privileged, or unprivileged user to access restricted functionality in the application.
@terriko raised this concern on public-webappsec:
The text was updated successfully, but these errors were encountered: