Closed (duplicate)
Project:
Drupal core
Version:
4.5.2
Component:
user.module
Priority:
Critical
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
4 Apr 2005 at 17:48 UTC
Updated:
4 Apr 2005 at 17:51 UTC
Please see http://drupal.org/node/19969 for details.
I think it's critical that some sort of personalized challenge system be implemented to before a user can submit a request new password. This represents a huge potential flaw that would allow a malicious user to harvest user account names and write a script that just keeps resetting passwords left and right - essentially locking out users from logging into their Drupal user accounts.
Comments
Comment #1
killes@www.drop.org commentedhttp://drupal.org/node/18719