A reset password link emailed to the user can be re-used within the hour after a password reset is requested for the user. An attacker with access to the user's email account or otherwise intercepts the link could successfully reset the user's account after the user's own reset.
A reset password link emailed to the user can be re-used within the hour after a password reset is requested for the user. An attacker with access to the user's email account or otherwise intercepts the link could successfully reset the user's account after the user's own reset.