9 points | by garyhtou 2 days ago
1 comments
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?