Hi,
if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.
This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.
Is there a way to fix it?
kind regards
此问题已终结
4262
查看
| 相关帖文 | 回复 | 查看 | 活动 | |
|---|---|---|---|---|
|
|
0
11月 25
|
3 | ||
|
|
2
9月 25
|
5560 | ||
|
|
0
10月 25
|
2178 | ||
|
|
1
4月 25
|
3602 | ||
|
|
0
12月 24
|
3834 |