L25 · level 0Session puzzling (forgot-password)— Submit a victim's email at /forgot-password, then browse straight to /dashboard — you are logged in as them (the admin's email yields an admin session). The security questions are never needed.
L13 · level 0Predictable reset tokens— Guess another user's reset token and take over the account.