• Resolved bt_dev

    (@biotrace)


    We have an unusual behaviour when activating a users account, the account activated email they receive contains the admins email as the account email and the admin user name as the account user name. But worst of all, the password reset link is a password reset link for the admins account, posing a significant security risk. A new user was able to reset the admins password using this malformed account activated email. 

    This is for ultimate member 2.3.10

Viewing 15 replies - 1 through 15 (of 17 total)
Viewing 15 replies - 1 through 15 (of 17 total)

The topic ‘bug report’ is closed to new replies.