Skip to Content
Menu
Dette spørgsmål er blevet anmeldt
2958 Visninger

Hi,

if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.

This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.

Is there a way to fix it?

kind regards

Avatar
Kassér
Related Posts Besvarelser Visninger Aktivitet
1
apr. 25
1601
0
dec. 24
1336
1
sep. 24
1223
3
maj 24
1947
1
feb. 24
3957