?
avatar PhilETaylor
PhilETaylor
8 Jan 2021

Steps to reproduce the issue

Use "Forgot your password" on frontend of Joomla 4 beta 6
enter a valid syntax email of a non-user Eg : No-Such-Email@example.com
Click Submit

Expected result

"If a user matched that email address then we sent an email to them"

Actual result

"Reset password failed: Invalid email address" because no user matched that email address

Screenshot 2021-01-08 at 14 18 19

System information (as much as possible)

Additional comments

Note that if a user EXISTS with the email address provided then the page redirects to
Screenshot 2021-01-08 at 14 20 01

avatar PhilETaylor PhilETaylor - open - 8 Jan 2021
avatar joomla-cms-bot joomla-cms-bot - change - 8 Jan 2021
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 8 Jan 2021
avatar PhilETaylor PhilETaylor - change - 8 Jan 2021
Title
[4b6][Security][Release Blocker] User Enumeration on frontend
[4b6][Security][Release Blocker] User Enumeration on frontend "Forgot your password"
avatar PhilETaylor PhilETaylor - edited - 8 Jan 2021
avatar wilsonge
wilsonge - comment - 8 Jan 2021

This code is line for line the same as j3. I haven't tested but struggle to believe this is j4 specific

avatar PhilETaylor
PhilETaylor - comment - 8 Jan 2021

I was asked to test Joomla 4 beta 6 - so I did and reported what I found.

As the JSST are so slow to respond to any security issue reported, Im not surprised. The last time I asked for an update (October 2020) I was told that TEN of my reports were still outstanding and unresolved.

Screenshot 2021-01-08 at 16 01 56

avatar PhilETaylor PhilETaylor - change - 8 Jan 2021
Title
[4b6][Security][Release Blocker] User Enumeration on frontend "Forgot your password"
[3][Security][Release Blocker] User Enumeration on frontend "Forgot your password"
avatar PhilETaylor PhilETaylor - edited - 8 Jan 2021
avatar wilsonge wilsonge - change - 8 Jan 2021
Status New Closed
Closed_Date 0000-00-00 00:00:00 2021-01-08 16:09:46
Closed_By wilsonge
avatar wilsonge wilsonge - close - 8 Jan 2021
avatar wilsonge
wilsonge - comment - 8 Jan 2021

Ancient PR is here #30787

avatar PhilETaylor
PhilETaylor - comment - 8 Jan 2021

/facepalm...

avatar PhilETaylor PhilETaylor - change - 13 Jan 2021
Title
[3][Security][Release Blocker] User Enumeration on frontend "Forgot your password"
[3] User Enumeration on frontend "Forgot your password"
avatar PhilETaylor PhilETaylor - edited - 13 Jan 2021

Add a Comment

Login with GitHub to post a comment