Actions
Bug #21277
closedDanger for misusing forgot password function for spamming mailboxes
Start date:
2009-10-15
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
When a user enters an unknown mail address in the forgot password field, a mail is sent to the given mail address telling you that it is unknown.
With this "feature" you can send mails to various recipients, which never got in touch with your website and can of course also be misused to spam somebody.
Please provide a patch with the possibility to disable this feature and display a message in FE instead. (like 'User is unknown')
(issue imported from #M12242)
Updated by Chris topher about 15 years ago
Hi Markus,
thanks for your report!
This has already been reported and discussed; see #11765.
If you have an idea how to solve the issue, please post it there!
Actions