Skip to content

Security Risk: Shared OTP Verification Route Can Lead to Password Mix-Up #1

Description

@pspriyanshu601

If the OTP verification route for both forgot password and login is shared, a potential security vulnerability arises. For instance, if someone registers for the first time while another user initiates a forgot password process simultaneously, there's a risk of mismatched passwords being saved. This could lead to unauthorized access, as the system might inadvertently associate the new password with the wrong user profile.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions