AndyB
Well-known member
- Affected version
- 2.2.10 Patch 1
Steps to reproduce:
Suggested fix: Don't send password reset email if email address of banned user is used in the password rest function.
Source: https://xenforo.com/community/threads/user-password-edited-by-other-user-account.208435/post-1588553
- Create 2 accounts
- Ban
account1
- Logout or open an incognito window and go to
/lost-password/
- Enter the email address of
account1
- Login as
account2
- Visit the password reset link, that you got for
account1
- Change the password
account1
(the banned one) you will see account2
(the one you changed the password with).Suggested fix: Don't send password reset email if email address of banned user is used in the password rest function.
Source: https://xenforo.com/community/threads/user-password-edited-by-other-user-account.208435/post-1588553
Last edited: