Vulnerability- No limit of incorrect attempts


It is possible to brute-force recovery code from email on SFIT-ERP as it doesn’t have an incorrect input limit. I have tried 80+ different combinations until I reached the 6 code user received on email.

Severity — Medium

Steps to Reproduce:-
1. Click “Reset…

Harsh Malhotra

A student interested in cyber security and making internet a more safer place :-)

