We found out, that it is possible to get user names from password reset link by guessing uid's.

I've did a little form alter to remove the username.
See the attached patch.

Cheers
Matthias

CommentFileSizeAuthor
#2 user_enumeration_reset_3056388_1.patch1.36 KBmfrosch

Comments

mfrosch created an issue. See original summary.

mfrosch’s picture

StatusFileSize
new1.36 KB
nicksanta’s picture

Assigned: Unassigned » nicksanta

This is a great find, thank you for providing a patch! I am writing some tests and will commit it to 8.x-1.x branch shortly.

  • nicksanta authored 35c8e04 on 8.x-1.x
    Issue #3056388 by mfrosch, nicksanta: Prevent User Enumeration from...
nicksanta’s picture

Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.