Skip to Content.
Sympa Menu

en - [sympa-users] sympa security problem

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: Riccardo Veraldi <address@concealed>
  • To: address@concealed
  • Subject: [sympa-users] sympa security problem
  • Date: Thu, 18 Apr 2013 12:42:40 +0200

Hello,
on my sympa server I have a problem

if a user points to this URL


https://mysympaserver.org/sympa/renewpasswd/

the users is prompted to insert his email for a lsot password.

but the form accepts ANY email also addresses which are not in the smypa user_table.

so any email address will receive a reply by sympa to reset the password.
the result is that a new user will be created.
how can I avoid this ?

thanks

Rick



  • [sympa-users] sympa security problem, Riccardo Veraldi, 04/18/2013

Archive powered by MHonArc 2.6.19+.

Top of Page