Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 293104

security issue: form "user_pass" password resetting - email/username exists disclosure

$
0
0

function user_pass_validate(); disclosure an exist of account and email address on the site.

how to reproduce:
https://drupal.site.com/user/password with captcha enabled. type any email/account you want to check

form errors:
What code is in the image? field is required.
Sorry, admin@sitename.com is not recognized as a user name or an e-mail address.


Viewing all articles
Browse latest Browse all 293104

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>