vc-platform
vc-platform copied to clipboard
Bug report Broken Authentication and Session Management (leads to account compromise if some conditions are met)
Hi, Steps to repro:
- Create an (virtocommerce) account having an email address "[email protected]".
- Now Logout and ask for a password reset link. Don't use the password reset link.
- Log in using the same password back and update your email address to "[email protected]" and verify the same.
- Now log out and use the password reset link which was mailed to "[email protected]" in step 2.
- Password will be changed. All previous password reset links should automatically expire once a user changes his email address. Please let me know if this can be fixed