跳至内容
菜单
此问题已终结
3111 查看

Hi,

if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.

This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.

Is there a way to fix it?

kind regards

形象
丢弃
相关帖文 回复 查看 活动
1
4月 25
1841
0
12月 24
1564
1
9月 24
1362
3
5月 24
2171
1
2月 24
4226