the second password reset request does not make sense at all. If the token is simply not checked, what is the point in doing a secondary password request for wiener, and then sending the request without a token and with username carlos. I did it without a secondary request.
it's not necessary to remove the token, just change the username and that's it :)
Thanks man 👍
the second password reset request does not make sense at all. If the token is simply not checked, what is the point in doing a secondary password request for wiener, and then sending the request without a token and with username carlos. I did it without a secondary request.
Thank you
Can you plzz provide a video for subdomain takeover and ssrf
It was needed to reset 2 times the password of wiener.