Please see http://drupal.org/node/19969 for details.

I think it's critical that some sort of personalized challenge system be implemented to before a user can submit a request new password. This represents a huge potential flaw that would allow a malicious user to harvest user account names and write a script that just keeps resetting passwords left and right - essentially locking out users from logging into their Drupal user accounts.

Comments

killes@www.drop.org’s picture