Security Vulnerability - Password Reset Link

The hub password reset link is still valid after the password has been reset. If the e-mail is intercepted an attacker can later reuse the link and reset the password to the hub.

1 Like

Tagging @bobbyD @gopher.ny

2 Likes

Noted.

4 Likes

Thanks for your feedback. Please see the PM, we would like to learn more about your findings.

2 Likes

I updated my e-mail address and can no longer get to the PM

I have merged the two accounts. You cannot change the email address, as it's a primary key in the platform's database. The system was flagging your posts because two users were replying to the same post from the same IP address. Let me know if you have any more problems.

1 Like