1. User Enumeration
  2. Missing Rate Limiting
  3. SQL Injection
  4. Cross-Site Scripting
  5. Text Injection/Content Spoofing
  6. HTML Injection in Email
  7. Password Reset Poisoning via Host Header Injection
  8. Re-usable Password Reset Token
  9. No Expiration on Password Reset Token
  10. Guessable Password Reset Token
  11. Security Question Bypass during Password Reset
    1. Direct Request
    2. Referrer Check Bypass
  12. Parameter Pollution
  13. Reset Token Leakage in Response
  14. Password Reset OTP Brute-Force
  15. Weak Cryptography in Reset Token Generation
  16. Insecure Direct Object Reference
  17. IDN Homograph Attack
  18. Account Takeovers
  19. Third-Party Leakage
  20. Weak Password Policy
  21. Insufficient Session Expiration on Password Change
  22. MFA Auto Disable after Password Reset
  23. MindMap By: Harsh Bothra Twitter: @harshbothra_ https://harshbothra.tech