Open
Description
I deploy Orangescrum following the guideline for docker https://hub.docker.com/r/orangescrum/orangescrum-app When I try to change the host to attacker in the request that reset pass throught email (use burp suite) then received email contain it.
=> This issue lead to TakeOver Account, so any solutions to fix it
Metadata
Assignees
Labels
No labels
Activity