reset password vulnerability
Posted: Sat May 08, 2021 2:44 pm
re:
https://forums.oscommerce.com/topic/496 ... erability/
This option only works if the user changes the password after logging in.
If the user changes the password using the forgotten password option, then all other sessions in different browsers still stay logged in.
This was checked using CE Frozen.
Has this hook been added to phoenix yet, I couldn't find it?
https://forums.oscommerce.com/topic/496 ... erability/
This option only works if the user changes the password after logging in.
If the user changes the password using the forgotten password option, then all other sessions in different browsers still stay logged in.
This was checked using CE Frozen.
Has this hook been added to phoenix yet, I couldn't find it?