
0-Click Account Takeover via Reset Password
During a pentesting engagement at Cyber AR, our team identified a critical vulnerability in a password reset flow that allowed an attacker to hijack any user’s account without needing the victim's int...
October 2, 20244 min read