?
avatar PhilETaylor
PhilETaylor
8 Jan 2021

Steps to reproduce the issue

Joomla 4 beta 6 tested
Frontend click "Forgot your username"

Enter a syntax valid email address of a non-registered user - Eg No-Such-Email@example.com
Click Submit

Expected result

"If a user was found with that email address, then we have sent them an email"

Actual result

User Enumeration ability based on response.

"Reminder failed: User not found."

Screenshot 2021-01-08 at 14 22 22

System information (as much as possible)

Additional comments

Note that if you use a email address of a registered user you get a different message

Screenshot 2021-01-08 at 14 22 44

avatar PhilETaylor PhilETaylor - open - 8 Jan 2021
avatar joomla-cms-bot joomla-cms-bot - change - 8 Jan 2021
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 8 Jan 2021
avatar PhilETaylor PhilETaylor - change - 8 Jan 2021
The description was changed
avatar PhilETaylor PhilETaylor - edited - 8 Jan 2021
avatar wilsonge
wilsonge - comment - 8 Jan 2021

Again the remind model is line for line the same as j3 so likely exists there too and not j4 specific

avatar PhilETaylor
PhilETaylor - comment - 8 Jan 2021

ok well Ive emailed security@joomla.org ... fingers crossed they make it for Joomla 3.9.24 as well then....

avatar PhilETaylor
PhilETaylor - comment - 8 Jan 2021

Its insane that this type of security issue has been around for years though....

avatar PhilETaylor PhilETaylor - change - 8 Jan 2021
Title
[4b6][Security][Release Blocker] User Enumeration on frontend "Forgot your username"
[3][Security][Release Blocker] User Enumeration on frontend "Forgot your username"
avatar PhilETaylor PhilETaylor - edited - 8 Jan 2021
avatar wilsonge wilsonge - change - 8 Jan 2021
Status New Closed
Closed_Date 0000-00-00 00:00:00 2021-01-08 16:09:35
Closed_By wilsonge
avatar wilsonge wilsonge - close - 8 Jan 2021
avatar wilsonge
wilsonge - comment - 8 Jan 2021

Ancient PR #30787

avatar PhilETaylor PhilETaylor - change - 13 Jan 2021
Title
[3][Security][Release Blocker] User Enumeration on frontend "Forgot your username"
[3] User Enumeration on frontend "Forgot your username"
avatar PhilETaylor PhilETaylor - edited - 13 Jan 2021

Add a Comment

Login with GitHub to post a comment