plainblack.com
Username Password
search
Bookmark and Share
View All Tickets
Email based password recovery allows resetting any users email  (#8790)
Issue

With email based password recovery, the user can enter either a username or an email, and it will mail a link to reset that users password.

If both are entered however, it will send a link to reset the user to the email entered, even if the email doesn't match the user's.  This allows you to reset the password for any user.

Attaching a patch for 7.4.

Fixed in 7.5.26, 7.6.1.

Solution Summary
Fixed in 7.5.26, 7.6.1.
Comments
Graham
0
10/9/2008 3:35 pm
Fixed in 7.5.26, 7.6.1.
Details
Ticket Status Resolved  
Rating0.0 
Submitted ByGraham 
Date Submitted2008-10-09 
Assigned To unassigned  
Date Assigned2021-01-09 
Assigned By 
Severity Cosmetic (misspelling, formatting problems)  
What's the bug in? WebGUI Stable  
WebGUI / WRE Version  
URLbugs/tracker/8790
Keywords
Related Files
Ticket History
10/9/2008
8:35 PM
Resolved Graham
10/9/2008
8:31 PM
Ticket created Graham
© 2021 Plain Black Corporation | All Rights Reserved