"Forgot Password" "Sending Email" Question "Forgot Password" "Sending Email" Question
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

"Forgot Password" "Sending Email" Question

Started by Jarvhix, September 17, 2005, 11:04:26 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Jarvhix

I' must ask this because to me it is important (thinking security) for members. Why would anyone be able to put in a user's name when they click on forgot password and then the system shows where they're sending the password to-- as in showing the user's email address. This means anyone can come in a get email address of users simply by knowing the user's name and clicking on the "forgot password" box. Is this something that cannot be fixed!!

casNuy


Jarvhix

ok, can you point me to the right forum? I'm confused as to where to post my question.

casNuy


Jarvhix

oh thanks. I just posted in a forum for "ecards & email". Maybe it too was the wrong forum. I will check out the link you sent m. Thanks.

Joachim Müller

Quote from: casNuy on September 18, 2005, 03:16:47 PM
suggest you go here :
http://forum.coppermine-gallery.net/index.php?board=12.0
this is wrong!

Quote from: Jewels on September 18, 2005, 03:23:32 PM
oh thanks. I just posted in a forum for "ecards & email". Maybe it too was the wrong forum.
No, posting there was correct.

Closing this thread now.