This lab's password reset functionality is vulnerable.
To solve the lab:
wiener:petercarlosusername: wienerpassword: peterWiener as the username and set a new password, for example, hacker./forgot-password?temp-forgot-password-token using the POST Method.temp-forgot-password-token=s8kx4aivncdm5fxpougtwysehn4zwvdv is not important for us to change Carlosβs password, as itβs for Wiener. Every user on the system has a unique token.Carlos and the password to victim?
username: carlospassword: victim