Hi,
if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.
This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.
Is there a way to fix it?
kind regards
この質問にフラグが付けられました
4246
ビュー
| 関連投稿 | 返信 | ビュー | 活動 | |
|---|---|---|---|---|
|
|
0
11月 25
|
3 | ||
|
|
2
9月 25
|
5551 | ||
|
|
0
10月 25
|
2172 | ||
|
|
1
4月 25
|
3599 | ||
|
|
0
12月 24
|
3826 |