Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by waloodi_109 - 25.11.2024
Last edited by cbay - 26.11.2024

FS#109 - Issue with password change

Issue with password change

Hello Team, i hope you are doing well. While, researching in your domain, i found issue with password change bug.

When a password is changed in user's profile, then a notification about password change is sent to the user (email).
However, user not always gets a notification about password change - when a password is changed via password reset link, then such a notification is not send to the user. In your domain notification not sent to user, when he/she change the password in profile setting and with reset password.

Thank You,

Waleed Anwar

Closed by  cbay
26.11.2024 11:01
Reason for closing:  Invalid
26.11.2024: A request to reopen the task has been made. Reason for request: Watch clearly i am already login into the account then i was change my password in profile setting and their is no notification was sent to the email that i registered
Admin
cbay commented on 26.11.2024 09:07

Hello,

When a password is changed in user's profile, then a notification about password change is sent to the user (email).

I do not believe that's true. Can you show me that email?

Kind regards,
Cyril

oky sir i will send it

Email is: ahali19127@gmail.com

Admin
cbay commented on 26.11.2024 10:37

I don't want your email address, I want you to copy/paste the email message that we supposedly send when a user changed its password.

i will make a video for easy understanding oky sir

here is the video sir

Admin
cbay commented on 26.11.2024 11:01

Your video shows no such email, as I suspected.

Watch clearly i am already login into the account then i was change my password in profile setting and their is no notification was sent to the email that i registered and when i request a forgot password then notification will be send to my registered email and when i was changing my password through that link password will be changed and there is no notification will be sent to my email

There is no email message sent to the user, when he/she will change his/her password via profile setting and with reset password link, please watch this issue clearly in your own end.

Reopen it and have a look on it, you will understood it clearly

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing