跳至內容
選單
此問題已被標幟
3274 瀏覽次數

Hi,

if you go to the login page of Odoo 13 click on reset password. and enter a mail address which is not valid you get an error message invalid email. If you enter a correct email address you get a different message.

This can be easily exploited by bruteforcing a list of emails to get an email registered at the Odoo app.

Is there a way to fix it?

kind regards

頭像
捨棄
相關帖文 回覆 瀏覽次數 活動
2
9月 25
2890
1
9月 25
428
1
4月 25
2035
0
12月 24
1883
1
9月 24
1547