1. Create an account on the target website.
  2. Logout from your account.
  3. Go to login page and click on forgot password.
  4. Enter your email and click on reset password.
  5. You should have email received in your inbox. Right click to copy link address for changing password.
  6. Keep the address saved somewhere.
  7. Now, change the password using the link.
  8. Try changing the password again using the same link at a incognito tab. If the password can be changed, there is a vulnerability.