It is a P4 category bug:
- Sensitive Data Exposure
- Weak Password Reset Implementation
- Password Reset Token Sent Over HTTP
How to Find
- Create user account.
- Sign in and sign out from your account.
- At the login page click on
forgot password. - Click on
request reset link. - Right click on
click to resetand clickcopy link address. - Paste it to new tab and if it is sent over HTTP, we have a bug