Se rendre au contenu
Menu
Cette question a été signalée

Hi,

if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.

This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.

Is there a way to fix it?

kind regards

Avatar
Ignorer
Publications associées Réponses Vues Activité
1
avr. 25
1881
0
déc. 24
1580
1
sept. 24
1373
3
mai 24
2198
1
févr. 24
4244