Skip to content

Enumeration attack from the Password Reset form #350

Open
@jonathan-s

Description

@jonathan-s

Describe the bug
This isn't a very serious security issue, however the best practice when it comes to password reset forms is that you don't give the user a reason to know whether an email exist in the database or not. Right not the user receives a validation error that says that the email doesn't exist.

Expected behavior
Instead the user should get the message If the email exists it will be sent to your email address.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions