It is a P4 category bug:
- Sensitive Data Exposure
- Weak Password Reset Implementation
- Password Reset Token Sent Over HTTP
How to Find
- Create user account.
- Sign in and sign out from your account.
- At the login page click on
forgot password
. - Click on
request reset link
. - Right click on
click to reset
and clickcopy link address
. - Paste it to new tab and if it is sent over HTTP, we have a bug