1 comment

[ 3.6 ms ] story [ 6.6 ms ] thread
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?