Page 1 of 1

reset password vulnerability

Posted: Sat May 08, 2021 2:44 pm
by Mikepo
re:
https://forums.oscommerce.com/topic/496 ... erability/

This option only works if the user changes the password after logging in.

If the user changes the password using the forgotten password option, then all other sessions in different browsers still stay logged in.

This was checked using CE Frozen.
Has this hook been added to phoenix yet, I couldn't find it?

Re: reset password vulnerability

Posted: Sat May 08, 2021 4:15 pm
by ecartz
The reason why that is a hook is so you can add it if you want that behavior.

I do not think that is a desirable behavior in general, so I have no intent to add this to core.