In the RESET-PASSWORD process, if the request's JSON allows adding values like an array:
it could be exploited to send the reset password link/code to an attacker's email, making it easy to take over the account.✅
{"email":["victim@test.com","attacker@test.com"]}it could be exploited to send the reset password link/code to an attacker's email, making it easy to take over the account.
Please open Telegram to view this post
VIEW IN TELEGRAM
❤5