Exploiting Password Reset Poisoning

Mike Brown
InfoSec Write-ups
Published in
3 min readNov 13, 2021

--

Photo by TheDigitalWay from Pixabay

To date, one of my most lucrative bug bounties came from a password reset poisoning vulnerability. This post walks through the process of finding, exploiting, and fixing this bug to help you earn a max payout in your own disclosures!

⭐️ Not a Medium member? Read the full article at m8sec.dev

Overview

--

--