❤1
In the RESET-PASSWORD process, if the request's JSON allows adding values like an array:
it could be exploited to send the reset password link/code to an attacker's email, making it easy to take over the account.✅
{"email":["[email protected]","[email protected]"]}it could be exploited to send the reset password link/code to an attacker's email, making it easy to take over the account.
Please open Telegram to view this post
VIEW IN TELEGRAM
❤5