envelopeA Password Reset Gone Wrong: Credentials Leaked via Raw Email

Second bug found in the wild

A Standard Password Reset

Viewing the Email in Raw Format

When a Header Contains More than Metadata

Why "It's Just a No-Reply Account" Still Matters

Responsible Disclosure

Remediation

  1. Removing Credentials from Email Configurations

  2. Proper Authentication for Mail Services

Last updated