Three new lessons just dropped: AI Slop-Squatting, CSS Injection, and CORS Try new lessons
Hacksplaining
Log in Sign up Train your team
Lesson:

Password Mismanagement

Public preview

Want everyone on your software team to learn this? Get completion tracking and compliance reporting with Hacksplaining for Teams. Free 14-day trial.

Train my team

Your site will typically implemented two password reset screens - one for logged out users (after clicking on a password reset link in an email), and one for users already logged in. Ensure this latter screen requires re-entering of the user's old password, in case they leave themselves logged in on a shared computer.

Internal reset screens should require the old password to be re-entered
Lab progress
14 / 23
Back Stage 14 of 23 Continue
Hacksplaining

Defend your code.

Learn

All Lessons AI Prompt Injection SQL Injection XSS CSRF

Teams

For Teams Features Pricing FAQ

Resources

Glossary OWASP Top 10 PCI Compliance Book

Legal

Privacy Terms DPA Subprocessors

© 2026 Hacksplaining. Built with in Seattle, WA, USA

About Us · Need help? Reach out to support@hacksplaining.com