Authentication and session management flaws that lead to account takeover.
Host: evil.com, does reset link become evil.com/reset?token=…?returnUrl, goto, return_url, back, returnTomyemail%00@email.com – null byte truncation to real email?id parameter, test HTTP Parameter Pollution“canEdit”:“false” JSON is enforced server-side or just client-side