Git Product home page Git Product logo

wlox-frontend's People

Contributors

ergofobe avatar mbassan avatar

Watchers

 avatar  avatar  avatar

wlox-frontend's Issues

FD-748 - Remove X-Powered-By header

From Freshdesk:

[+]Bug : X-Powered-By-Header

The webserver sends the used PHP version in the X-Powered-By header. This leads to some basic info leaks regarding to the system software,You should remove this specific response header.

FD-759 - Creating a 2nd password reset token does not invalidate the 1st token

From FD-759:

Suppose someone used the forget password options of 1btcxe to change his password.Then he will get a token in his email address.Let it call token
1.Now think that he didn't use the token1 and then again used the forget password option.Now he will get another token.Let it call token 2.Now he uses token2.The industry standard procedure is,when someone issues a new token,the old one automatically become expire.But in case of 1btcxe its not happening.Even after the issuance and using of token 2 ,the previous token remains valid for use. I can demonstrate an attack scenario if you want.

Thanks & Regards

Ashish Pathak

Misaligned + symbol

The + symbol on the Add Crypto Capital account is slightly mis-alligned vertically.

screenshot 2014-11-19 at 2 10 29 pm

Best price self orders detection

When a user places a market order which he is also the best price, the confirmation page shows his best price, but executes the order with the next best price.

Invalid link on Chinese translation

The 新闻 link on the footer of the chinese translation links to 新闻新闻.php, triggering a 404 error, but should link to 新闻.php (I think).

FD-722 - Login after password reset token request does not invalidate password reset link

From FreshDesk:

Hello there team
This is Shahmeer and i found out about an issue in the Password reset link and the session validation.
To reproduce
Request a password reset link to a sample account
Login after requesting the link
The password reset link that was generated will not be invalidated and you can still use it.
Attack Scenario:
After POST of the victim's email. the attacker requests a password reset link
The victim logs in to change the email but the attacker can still use the link to change the original password
I think this should be timely fixed

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.