Hacker News new | ask | show | jobs
by Shivetya 2641 days ago
I am just amazed, provided I am reading this right, that anyone can simply with a bit of code overwrite any user password on the site.

you would think there would different levels of user accounts and perhaps two level authentication for any change regardless of how it is invoked

1 comments

There are user levels. But if you can execute code on the site ... any site, what difference does that make?