email enumeration enabled leading to unauthorized login attempts and account lockout

Disclosed by
xabit___
Summary by National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program

That is not how the forgot password function work. Leveraging this will never "lockout" a user.

Summary by xabit___

disclose

Activity