|
|
|
|
|
by nbpoole
4986 days ago
|
|
I have no Django experience, but I can imagine how an attack like this works: 1. Links are rendered via some function that takes into account the user's current request (ie: to determine the proper host) 2. The "reset your password by clicking this link" URL is generated using that function. 3. I am a malicious attacker and I submit a password reset request for your account. Thus, I can control the URL that is sent to you in an email. |
|
[So please upgrade!]