Subject: The mailing list for listmasters using Sympa
List archive
- From: Riccardo Veraldi <address@concealed>
- To: address@concealed
- Subject: [sympa-users] sympa security problem
- Date: Thu, 18 Apr 2013 12:42:40 +0200
Hello,
on my sympa server I have a problem
if a user points to this URL
https://mysympaserver.org/sympa/renewpasswd/
the users is prompted to insert his email for a lsot password.
but the form accepts ANY email also addresses which are not in the smypa user_table.
so any email address will receive a reply by sympa to reset the password.
the result is that a new user will be created.
how can I avoid this ?
thanks
Rick
- [sympa-users] sympa security problem, Riccardo Veraldi, 04/18/2013
Archive powered by MHonArc 2.6.19+.