Steam games need to store save files in the same library location as the game, using a sub folder that maps to the steam account name. Stop filling up the app data folder for the operating system account that is running steam. My C drive is full, go away.
That password reset looked to be like step four of something. So it’s a business logic bypass. Still awful of course but slightly more understandable given other ways this vulnerability could have been introduced. The cool part was detecting all the steps completely blackbox because everything was in the Javascript.
There is no excuse for issuing a valid token before mfa succeeds though. That is negligent.