Back to News
Advertisement
Advertisement

Discussion (1 Comments)Read Original on HackerNews

Noujinabout 6 hours ago
Why the hell does nobody talk about the crazy exploitation way? Calling the reset password endpoint, triggering a 400 but receiving an active session through that? Did they inject a compromised email?