Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Bug? Reveal user email through Forgotten my password
Yeah, just checked out again.
1. I'm a registered and logged in member.
2. I checkout someone's personal account page and see email - n/a
I can't see someone's email even if i'm registered and logged in - spam countermeasure, right?
1. I'm not logged in (registration doesn't matter).
2. I goto Sign In screen, Click Forgot Password and enter someone's username and then i see his email revealed in a message saying that instructions have been mailed to his inbox.
Even unlogged user can see someone's email address
1. I'm a registered and logged in member.
2. I checkout someone's personal account page and see email - n/a
I can't see someone's email even if i'm registered and logged in - spam countermeasure, right?
1. I'm not logged in (registration doesn't matter).
2. I goto Sign In screen, Click Forgot Password and enter someone's username and then i see his email revealed in a message saying that instructions have been mailed to his inbox.
Even unlogged user can see someone's email address
My suggestion
Just remove the email address from that message. Or maybe add a captcha to forgot my password screen.0
This discussion has been closed.
Comments
there's a lot scripts and plugins for blogs (i use Textpattern) that do this like this somefunction("my@email.addr") or somefunction(variable_with_mail_address) to zazzle the output through javascript..
or display a domain name. but this won't help me, i have 4 accounts on gmail.com, you see..
just was browsing around some of your Vanilla Extensions and tried your username.
sorry