Open
Description
@terriko raised this concern on public-webappsec:
I do wonder if we should (non-normatively) mention the concern that having a well-known password change url could be used for nefarious purposes (e.g. sending a lot of emails, denial of service if there’s a rate limit on password changes, authentication attacks against security questions, etc.).
Metadata
Metadata
Assignees
Labels
No labels