Skip to content

There was an error resetting the password #126

@L-1-q

Description

@L-1-q

Is there a problem with the logic at reset.php?
As long as you guess the correct username, you can change the password without user permission.
Although the password cannot be guessed, the continuous modification will cause the user to be unable to log in.
I think there is still some impact.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions