Skip to Content
मेन्यू
This question has been flagged
3123 Views

Hi,

if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.

This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.

Is there a way to fix it?

kind regards

Avatar
Discard
Related Posts Replies Views Activity
1
अप्रैल 25
1881
0
दिस॰ 24
1578
1
सित॰ 24
1371
3
मई 24
2197
1
फ़र॰ 24
4242