AndyB
Well-known member
- Affected version
- 2.2.10 Patch 1
Steps to reproduce:
Suggested fix: Don't send password reset email if email address of banned user is used in the password rest function.
Source: https://xenforo.com/community/threads/user-password-edited-by-other-user-account.208435/post-1588553
- Create 2 accounts
- Ban
account1 - Logout or open an incognito window and go to
/lost-password/ - Enter the email address of
account1 - Login as
account2 - Visit the password reset link, that you got for
account1 - Change the password
account1 (the banned one) you will see account2 (the one you changed the password with).Suggested fix: Don't send password reset email if email address of banned user is used in the password rest function.
Source: https://xenforo.com/community/threads/user-password-edited-by-other-user-account.208435/post-1588553
Last edited: