Lab: Password reset broken logic
Last updated
Last updated
login as wiener password peter
then logout as wiener
click forgot password
when we visited the client email
we can see the password reset
try login as wiener with password
success
Now we can see the request of forgot password or change password
The token is actually not connected to the username account
So if we just change it to any other value
We can set a new password for that user
try login as wiener
success again
therefore we can exploit other account name or usename
to change their password
CHANGE THE PASSWORD OF CARLOS
which in the first place we dont know the password of that user
try login as carlos
its a success we can login as different user