7 points | by garyhtou 17 hours ago ago
1 comments
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?